Communication device, control method, and program
The communication device dynamically adjusts its power state for authentication, ensuring successful completion and reducing power consumption by using higher processor frequencies when necessary, addressing authentication failures and power inefficiencies.
Patent Information
- Authority / Receiving Office
- JP · JP
- Patent Type
- Patents
- Current Assignee / Owner
- Filing Date
- 2021-09-30
- Publication Date
- 2026-03-26
AI Technical Summary
Authentication processes in communication devices fail when transitioning from normal power mode to power-saving mode due to incomplete CPU clock frequency reduction, leading to increased power consumption if kept in normal mode.
A communication device dynamically switches its power state based on connection requirements, using a higher processor frequency for authentication and transitioning to a second state for specific authentication methods without changing power modes.
This approach ensures successful authentication while optimizing power consumption by dynamically adjusting the power state of the communication device.
Smart Images

Figure 0007836163000001 
Figure 0007836163000002 
Figure 0007836163000003
Abstract
Description
Technical Field
[0001] The present invention relates to a communication device, a control method, and a program capable of communicating with an external device that requires authentication.
Background Art
[0002] In a communication device, a process of connecting to an access point existing around the device may be executed. Patent Document 1 describes an information processing device that searches for connectable access points, displays an SSID list, and connects to the access point of the selected SSID. Further, in a communication device, when shifting from a normal power mode to a power saving mode, a process of reducing the clock frequency of the CPU may be executed. Patent Document 2 describes a communication device that shifts to different power saving modes according to the state of a session when the conditions for shifting to the power saving mode are satisfied.
[0003] By the way, in a wireless communication method using a wireless LAN based on the IEEE802.11 standard, it is known to protect a network by authenticating a communication device connected to the network. For example, as such an authentication method, the IEEE802.1X / EAP authentication method is known.
Prior Art Documents
Patent Documents
[0004]
Patent Document 1
Patent Document 2
Summary of the Invention
Problems to be Solved by the Invention
[0005] If the above authentication process is performed while the communication device has switched from normal power mode to power-saving mode and the CPU clock frequency has been reduced, the authentication process may not be completed within the specified time, resulting in authentication failure. On the other hand, keeping the communication device in normal power mode at all times will increase power consumption.
[0006] The present invention aims to provide a communication device, a control method, and a program that dynamically switch the power state of the communication device in response to connection with an external device requiring authentication. [Means for solving the problem]
[0007] To solve the above problems, the present invention provides a communication device which, when the communication device is operating in a first state in which the processor of the communication device operates at a first operating frequency, uses an authentication server 1 Supports authentication processing using the authentication method. 1 Based on the commencement of processing for connection between the external device and the communication device, the state of the communication device is transitioned to a second state in which the processor of the communication device operates at a second operating frequency higher than the first operating frequency. height, In the state in which the communication device is operating in the second state, 1 Authentication by the authentication method described above 1 Execute via an external device Control to control The means includes, and the control means is, When the communication device is operating in the first state, based on the fact that a process for connecting the communication device with a second external device corresponding to an authentication process using a second authentication method different from the first authentication method is initiated, the system controls the communication device to perform authentication using the second authentication method via the second external device without transitioning the state of the communication device to the second state. It is characterized by the following: [Effects of the Invention]
[0008] According to the present invention, the power state of the communication device can be dynamically switched in response to connection with an external device requiring authentication. [Brief explanation of the drawing]
[0009] [Figure 1] This diagram shows the system configuration. [Figure 2] This diagram shows the external configuration of an MFP (Multi-Function Product Processor). [Figure 3]It is a block diagram showing the configuration of the MFP. [Figure 4] It is a diagram schematically showing the configuration of the operation display unit of the MFP. [Figure 5] It is a diagram showing the external configuration of the information processing apparatus. [Figure 6] It is a diagram showing the configuration of the information processing apparatus. [Figure 7] It is a block diagram showing the configuration of the access point. [Figure 8] It is a diagram showing the configuration of the authentication server. [Figure 9] It is a flowchart showing the outline of the process of connecting the MFP to a network constituted by an access point. [Figure 10] It is a diagram for explaining the network between devices. [Figure 11] It is a diagram for explaining the screen transition in the operation display unit of the MFP. [Figure 12] It is a diagram for explaining the screen transition in the information processing apparatus. [Figure 13] It is a flowchart showing the process of connecting the MFP to a network constituted by an access point. [Figure 14] It is a flowchart showing the process of changing the power mode of the MFP. [Figure 15] It is a flowchart showing the process of changing the operating frequency of the MFP. [Figure 16] It is a flowchart showing the process of changing the operating frequency of the MFP.
Mode for Carrying Out the Invention
[0010] Hereinafter, embodiments will be described in detail with reference to the accompanying drawings. Note that the following embodiments do not limit the invention according to the claims. Although a plurality of features are described in the embodiments, not all of these plurality of features are essential to the invention, and the plurality of features may be arbitrarily combined. Further, in the accompanying drawings, the same or similar configurations are denoted by the same reference numerals, and redundant explanations are omitted.
[0011] [First Embodiment] FIG. 1 is a diagram showing an example of the system configuration in the present embodiment. The communication system 100 is a communication system in which a plurality of communication devices can communicate with each other wirelessly. As shown in FIG. 1, the communication system 100 includes an information processing device 200, a MFP (Multi Function Peripheral) 300, an access point (AP) 400, and an authentication server 500 as communication devices. In the communication system 100, the information processing device 200 and the MFP 300 can execute processes corresponding to the printing service, for example, using wireless LAN communication.
[0012] The information processing device 200 is an information processing device having a communication function such as wireless LAN or wired LAN. Note that wireless LAN may be called WLAN. As the information processing device 200, for example, a smartphone, a notebook PC, a tablet terminal, or a PDA (Personal Digital Assistant) is used.
[0013] The MFP 300 is an example of a printing device having a printing function. The MFP 300 may have a reading function (scanner), a FAX function, or a telephone function. Further, the MFP 300 has a communication function capable of wireless communication with the information processing device 200. In the present embodiment, the MFP 300 will be described, but a device having a different form from the MFP 300 may be used. For example, a facsimile device, a scanner device, a projector, a mobile terminal, a smartphone, a notebook PC, a tablet terminal, a PDA, a digital camera, a music playback device, a television, a smart speaker, an AR glass, etc. having a communication function may be used.
[0014] Access point 400 is a communication device that is installed separately (externally) from the information processing device 200 and MFP300 and operates as a base station device for the WLAN. Access point 400 may also be referred to as the external access point 400 or the external wireless base station. Communication devices with WLAN communication capabilities can communicate in WLAN infrastructure mode via access point 400. Infrastructure mode may also be referred to as "wireless infrastructure mode." In other words, wireless infrastructure mode is a mode in which a communication device communicates with the information processing device 200 via the access point 400 to which it is connected. Access point 400 communicates with communication devices that it has authorized to connect to (authenticated) and relays wireless communication between those communication devices and other communication devices. Furthermore, access point 400 is connected to a wired LAN communication network and relays communication between communication devices connected to that network and other communication devices wirelessly connected to access point 400. Furthermore, if the network configured by access point 400 uses an authentication server (i.e., access point 400 supports authentication methods that use an authentication server), it will work in conjunction with the authentication server 500 to authenticate communication devices connected to the network and control access to them. Communication devices connected to the network configured by access point 400 cannot communicate with any device other than the authentication server 500 until they are authenticated. Note that access point 400 may also support authentication methods that do not use an authentication server. Details on authentication methods that use an authentication server and authentication methods that do not use an authentication server will be described later.
[0015] The authentication server 500 is a communication device that is installed separately (externally) from the information processing device 200, MFP 300, and access point 400, and operates as an authentication server that centrally manages authentication information. The authentication server 500 works in cooperation with the access point 400 to authenticate terminals to be authenticated and controls terminal access based on the authentication results. The authentication server 500 is configured to perform authentication processing compliant with, for example, the IEEE 802.1X standard.
[0016] Access point 400 supports authenticators in IEEE 802.1X. Information processing unit 200 and MFP300 support supplicants in IEEE 802.1X. The authentication server is sometimes referred to as the "Radius server."
[0017] Authentication server 500 performs authentication according to the IEEE 802.1X standard, for example, using the EAP-TLS, EAP-TTLS, and PEAP methods. EAP-TLS (EAP-Transport Layer Security) is an authentication method that utilizes the TLS handshake protocol and performs authentication using server certificates and client certificates. EAP-TTLS (EAP-Tunneled TLS) is an authentication method that utilizes the TLS handshake protocol and performs authentication using server certificates, usernames, and passwords. PEAP (Protected EAP) performs authentication using usernames and passwords. The information used for these IEEE 802.1X authentication methods is sometimes collectively referred to as "authentication information."
[0018] The information processing device 200 and the MFP300 can perform wireless communication using their respective WLAN communication functions, either via the external access point 400 in wireless infrastructure mode or via peer-to-peer mode without the external access point 400. The peer-to-peer mode is sometimes referred to as "P2P mode," or as "wireless direct mode" in contrast to wireless infrastructure mode. In other words, P2P mode is a mode for communication devices to communicate directly with the information processing device 200 without going through the access point 400. P2P mode includes Wi-Fi Direct® mode and software access point (soft AP) mode, among others. Wi-Fi Direct® is sometimes referred to as WFD. Therefore, wireless direct mode can also be considered a communication mode compliant with the IEEE 802.11 series.
[0019] Figure 2 shows an example of the external configuration of the MFP300. The power button 301 is a hard key that allows the user to turn the power on and off. The operation display unit 302 includes a display and buttons used by the user when operating the MFP300. The operation display unit 302 includes keys such as character input keys, cursor keys, select keys, and cancel keys, as well as LEDs (Light Emitting Diodes) and LCDs (Liquid Crystal Displays). The operation display unit 302 is configured to accept user input when activating individual functions of the MFP300, changing various settings, etc. The operation display unit 302 may also include a touch panel display.
[0020] The paper insertion slot 303 is an insertion slot that can accommodate paper of various sizes. Paper placed in the paper insertion slot 303 is transported to the printing unit one sheet at a time, printed as desired, and then ejected from the paper output slot 304. The document tray 305 is a transparent glass-like tray used when scanning a document. The document cover 306 is a cover that presses the document against the document tray to prevent it from lifting during scanning, and also prevents external light from entering the scanner unit.
[0021] The MFP300 has communication capabilities via WLAN and wired LAN, and includes a wireless communication unit 307 and a wired communication unit 321, which include antennas for wireless communication. Note that the wireless communication unit 307 and the wired communication unit 321 do not necessarily have to be configured to be visible from the outside. The USB communication unit 308 includes a circuit and USB connector for the MFP300 to communicate with an external information processing device 200 or the like via USB connection. The power supply unit 309 connects to an external power supply and supplies power to the MFP300.
[0022] Figure 3 is a block diagram showing an example of the configuration of the MFP300. The MFP300 includes a main board 310 that controls the entire device, a power button 301, an operation display unit 302, a communication unit 322, a USB communication unit 308, and a power supply unit 309.
[0023] The main board 310 is equipped with a microprocessor-type CPU 311. The CPU 311 controls the MFP 300 according to the control program stored in the ROM-type program memory 313 connected via the internal bus 312 and the contents stored in the RAM-type data memory 314. The operation of the MFP 300 described in this embodiment is realized, for example, by the CPU 311 reading and executing the program stored in the program memory 313. The CPU 311 controls the scan unit 317 to read the document and stores the read data in the image memory 315 in the data memory 314. The CPU 311 controls the print unit 316 to print the image of the read data stored in the image memory 315 in the data memory 314 onto the recording medium. The CPU 311 controls the USB communication unit 308 via the USB communication control unit 320 to perform USB communication with the external information processing device 200 via a USB connection. The CPU 311 controls the operation control unit 319 to receive operation information from the power button 301 and the operation display unit 302. The CPU 311 controls the operation control unit 319 to display, for example, the status of the MFP 300 and the function selection menu on the operation display unit 302. Based on the operation information received by the operation display unit 302, the CPU 311 controls the wireless communication unit 307 and the wired communication unit 321 within the communication unit 322 via the communication control unit 318. For example, the CPU 311 changes the communication method settings and configures network connection settings based on the operation information. The CPU 311 also controls the power mode control unit 325 to switch the power mode of the MFP 300. The power mode switching operation will be described later.
[0024] The wireless communication unit 307 is a unit capable of providing WLAN communication functionality. Specifically, the wireless communication unit 307 converts data into packets according to WLAN standards and transmits these packets to other communication devices. Furthermore, the wireless communication unit 307 restores packets from other external communication devices back to their original data and outputs it to the CPU 311. The wireless communication unit 307 is configured to perform data (packet) communication in a WLAN system compliant with, for example, the IEEE 802.11 standard series (IEEE 802.11a / b / g / n / ac / ax, etc.). However, it is not limited to this configuration, and the wireless communication unit 307 may also perform communication in WLAN systems compliant with other standards. In this embodiment, the wireless communication unit 307 can communicate in both the 2.4GHz and 5GHz frequency bands. The wireless communication unit 307 can also perform communication in WFD mode, soft AP mode, wireless infrastructure mode, etc. The operation of these modes will be described later. Furthermore, the information processing device 200 and the MFP 300 are capable of wireless communication based on WFD mode, and the wireless communication unit 307 has a soft AP function or a group owner function. In other words, the wireless communication unit 307 can build a communication network in P2P mode and determine the channel to be used for communication in P2P mode.
[0025] The wired communication unit 321 is a unit for performing wired communication. The wired communication unit 321 can perform data (packet) communication in a wired LAN (Ethernet) system compliant with, for example, the IEEE 802.3 series. Furthermore, wired communication using the wired communication unit 321 is possible in wired communication mode. The wired communication unit 321 is connected to the main board 310 via a bus cable or the like.
[0026] The communication unit 322 is a unit capable of providing WLAN and wired LAN communication functions, and is composed of a wireless communication unit 307 and a wired communication unit 321. The communication unit 322 performs encryption and decryption processing during the authentication process when connecting to the access point 400. For example, when the communication unit 322 performs authentication using the WPA2-PSK method, it performs encryption and decryption processing in the 4-way Handshake. Also, when the communication unit 322 performs IEEE802.1X / EAP authentication processing, it performs encryption and decryption processing using RSA encryption or ECC (Elliptic curve Cryptography) encryption in the TLS handshake. Furthermore, the communication unit 322 performs encryption and decryption processing using symmetric key encryption for communication between the MFP 300 and the access point 400. As shown in Figure 3, the communication unit 322 is composed of a CPU 323 and program memory 324 dedicated to the communication unit 322, separate from the CPU 311 and program memory 313. Furthermore, if CPU 311 and program memory 313 also function as CPU 323 and program memory 324, then CPU 323 and program memory 324 are not required.
[0027] Figure 4 is a schematic diagram showing an example of the configuration of the operation display unit 302 of the MFP300. Figure 4(a) shows an example in which the operation display unit 302 is configured with a touch panel display 331. Power is turned on to the MFP300 when the user presses the power button 301. When power is turned on to the MFP300, the MFP300 operates in the normal power mode described later, and the touch panel display 331 displays the home screen, which is the highest level of the menu that the user can operate. The home screen includes a copy area 335 for receiving instructions to execute copy processing, a scan area 336 for receiving instructions to execute scan processing, and a print area 337 for receiving instructions to execute print processing. The home screen also includes a status display area 332 that shows the settings for connection via wireless infrastructure mode and wireless direct mode of the MFP300, and the status of those connections. The home screen also includes a connection setting mode area 333 in which the user can start the connection setting mode at any time, and a setting area 334 in which various settings can be changed.
[0028] Figure 4(b) shows an example of an operation display unit 302 configured with a relatively small LCD display 341 and various hard keys 344-351. Power is turned on to the MFP 300 when the user presses the power button 301. When power is turned on to the MFP 300, the home screen, which is the highest level of the user-operable menu, is displayed on the LCD display 341. The user can operate the cursor displayed on the LCD display 341 by pressing the cursor movement buttons 346 and 347. The user presses the OK button 349 to perform an operation, and the back button 348 to return to the previous menu screen. Also, when the user presses the QR button 344, a QR code containing the information necessary to directly connect to the MFP 300 is displayed. When the displayed QR code (registered trademark) is read by the information processing device 200, a direct connection is established between the information processing device 200 and the MFP 300, enabling wireless communication between them. Additionally, the connection setting mode can be started by pressing the connection setting mode button 345. In connection setting mode, the MFP 300 can be connected to the access point 400 by sending connection information from the information processing device 200 to the MFP 300. If the user presses the stop button 350 while the MFP 300 is performing any of the processes, the processes will be canceled. When the user presses the copy start button 351, the document placed on the document glass 305 is scanned and printing is performed.
[0029] Figure 4(c) shows an example of an operation display unit 302 configured with a relatively small LCD display 361 and various hard keys 363-370. Power is turned on to the MFP 300 when the user presses the power button 301. When power is turned on to the MFP 300, the home screen, which is the highest level of the user-operable menu, is displayed on the LCD display 361. The user can operate the items displayed on the LCD display 361 by pressing the navigation buttons 364 and 365. The user presses the OK button 367 to perform an operation, and the back button 366 to return to the previous menu screen. In addition, the connection setting mode can be started when the user presses the connection setting mode button 363. In connection setting mode, the MFP 300 can be connected to the access point 400 by sending connection information from the information processing device 200 to the MFP 300. If the user presses the stop button 368 while the MFP 300 is executing any process, the process is canceled. When the user presses the copy start button 369, the document placed on the document glass 305 is scanned and printing is performed. When the user presses the settings button 370, the user can change various settings.
[0030] Figure 5 shows an example of the external configuration of the information processing device 200. In this embodiment, the information processing device 200 is described as a typical smartphone (mobile terminal). The information processing device 200 is composed of, for example, a display unit 202, an operation unit 203, and a power key 204. The display unit 202 is a display that includes, for example, an LCD (Liquid Crystal Display) type display mechanism. The display unit 202 may also display information using, for example, an LED (Light Emitting Diode). In addition to or instead of the display unit 202, the information processing device 200 may also have a speaker function that outputs information by sound. The operation unit 203 is composed of hard keys such as keys and buttons, a touch panel, etc., for detecting user operations. In this embodiment, since the information display on the display unit 202 and the reception of user operations by the operation unit 203 are performed using a common touch panel display, the display unit 202 and the operation unit 203 are realized by a single device. In this case, for example, button icons or a software keyboard are displayed using the display function of the display unit 202, and the operation reception function of the operation unit 203 detects when the user touches these areas. The display unit 202 and the operation unit 203 may be separated, with separate hardware for display and hardware for operation reception. The power key 204 is a hard key for receiving user input to turn the power of the information processing device 200 on or off.
[0031] The information processing device 200 has a wireless communication unit 201 that provides WLAN communication functionality, as shown in Figure 6. The wireless communication unit 201 is configured to perform data (packet) communication in a WLAN system compliant with, for example, the IEEE 802.11 standard series (IEEE 802.11a / b / g / n / ac / ax, etc.). However, it is not limited to this, and the wireless communication unit 201 may also be able to perform communication in a WLAN system compliant with other standards. In this embodiment, the wireless communication unit 201 is capable of communicating in both the 2.4GHz and 5GHz frequency bands. Furthermore, the wireless communication unit 201 is capable of performing communication in WFD mode, soft AP mode, wireless infrastructure mode, etc. The operation of these modes will be described later.
[0032] Figure 6 shows an example of the configuration of the information processing device 200. The information processing device 200 includes a main board 211 that controls the entire device, a wireless communication unit 201 that performs WLAN communication, a display unit 202, an operation unit 203, and a short-range wireless communication unit 205 that performs wireless communication different from that of the wireless communication unit 201. The main board 211 includes, for example, a CPU 212, ROM 213, RAM 214, image memory 215, data conversion unit 216, telephone unit 217, GPS 219, camera unit 221, non-volatile memory 222, data storage unit 223, speaker unit 224, and power supply unit 225. GPS is an abbreviation for Global Positioning System. Each functional unit within the main board 211 is interconnected via a system bus 228. In addition, the main board 211 and the wireless communication unit 201, and the main board 211 and the short-range wireless communication unit 205 are connected, for example, via a dedicated bus. Furthermore, the main board 211 and the display unit 202, and the main board 211 and the operation unit 203 are connected, for example, via a dedicated bus.
[0033] The CPU 212 is the system control unit and controls the entire information processing device 200. The operation of the information processing device 200 described in this embodiment is realized, for example, by the CPU 212 reading and executing a program stored in the ROM 213. Dedicated hardware may be provided for each process. The ROM 213 stores control programs and embedded operating system (OS) programs executed by the CPU 212. Software control such as scheduling and task switching is performed by the CPU 212 executing each control program stored in the ROM 213 under the management of the embedded OS stored in the ROM 213. The RAM 214 is composed of SRAM (Static RAM) or the like. The RAM 214 stores data such as program control variables, user-registered settings, and management data for the information processing device 200. The RAM 214 may also be used as a buffer for various work. The image memory 215 is composed of memory such as DRAM (Dynamic RAM). The image memory 215 temporarily stores image data received via the wireless communication unit 201 and image data read from the data storage unit 223 for processing by the CPU 212. The non-volatile memory 222 is composed of memory such as flash memory and continues to store data even when the power to the information processing device 200 is turned off. Note that the memory configuration of the information processing device 200 is not limited to the above configuration. For example, the image memory 215 and RAM 214 may be shared, or data backup may be performed using the data storage unit 223. In this embodiment, DRAM is given as an example of image memory 215, but other storage media such as hard disks or non-volatile memory may be used.
[0034] The data conversion unit 216 performs data analysis of various data formats and data conversions such as color conversion and image conversion. The telephone unit 217 controls the telephone line and processes audio data input and output via the speaker unit 224, which includes a microphone and speaker, to realize telephone communication. The GPS 219 receives radio waves transmitted from satellites and acquires positional information such as the current latitude and longitude of the information processing device 200. The camera unit 221 has the function of electronically recording and encoding images input through the lens. Image data obtained by imaging with the camera unit 221 is stored in the data storage unit 223. The speaker unit 224 controls the input and output of audio for telephone functions and other functions such as alarm notifications. The power supply unit 225 is, for example, a portable battery and controls the power supply to the device. The power state of the information processing device 200 includes, for example, a battery-dead state where there is no remaining battery power, a power-off state where the power key 204 is not pressed, a normal startup state, and a power-saving state where it is running but in power-saving mode. The display unit 202 electronically controls the display content and performs control to display various input content, the operating status of the MFP300, status status, etc. The operation unit 203 receives user input and performs control such as generating an electrical signal corresponding to that input and outputting it to the CPU 212.
[0035] The information processing device 200 uses the wireless communication unit 201 to perform wireless communication and data communication with other communication devices such as the MFP 300. The wireless communication unit 201 converts data into packets and transmits the packets to other communication devices. The wireless communication unit 201 also restores packets from other external communication devices to their original data and outputs it to the CPU 212. The wireless communication unit 201 is a unit that realizes communication compliant with standards such as WLAN. The short-range wireless communication unit 205 communicates using a different communication method than the wireless communication unit 201, for example, Bluetooth®.
[0036] Figure 7 is a block diagram showing an example configuration of an access point 400 having wireless LAN access point functionality. The access point 400 includes a main board 410 that controls the access point 400, a wireless communication unit 420, a wired communication unit 421, and operation buttons 422.
[0037] The main board 410 is equipped with a microprocessor-type CPU 411. The CPU 411 operates according to the control program stored in the ROM-type program memory 412, which is connected via the internal bus 418, and the contents stored in the RAM-type data memory 413. In this embodiment, the operation of the access point 400 is realized, for example, by the CPU 411 reading and executing the program stored in the program memory 412. The CPU 411 performs wireless LAN communication with other communication devices by controlling the wireless communication unit 420 via the wireless communication control unit 414. The CPU 411 also performs wired LAN communication with other communication devices by controlling the wired communication unit 421 via the wired communication control unit 415. The CPU 411 accepts user operations via the operation button 422 via the operation control circuit 416.
[0038] The access point 400 includes a terminal access control unit 417. The terminal access control unit 417 protects the network by authenticating communication devices connected to the network. The terminal access control unit 417 authenticates communication devices connected to the network using various methods. These methods include, for example, the PSK method using a pre-shared key, the SAE method using SAE (Simultaneous Authentication of Equals), and the EAP method using an IEEE 802.1X / EAP compliant authentication server 500.
[0039] Figure 8 shows an example of the configuration of the authentication server 500. The authentication server 500 includes a main board 511 that controls the authentication server 500, a communication unit 501 that performs wired LAN communication, etc., a display unit 502, and an operation unit 503. The main board 511 includes a CPU 512, ROM 513, RAM 514, image memory 515, non-volatile memory 516, data storage unit 518, and communication control unit 517. Each functional unit within the main board 511 is interconnected via a system bus 519. In addition, the main board 511 and the communication unit 501, the main board 511 and the display unit 502, and the main board 511 and the operation unit 503 are connected, for example, via dedicated buses.
[0040] The CPU 512 is the system control unit and controls the entire authentication server 500. In this embodiment, the operation of the authentication server 500 is realized, for example, by the CPU 512 reading and executing a program stored in the ROM 513. Dedicated hardware may be provided for each process. The ROM 513 stores control programs and embedded operating system (OS) programs executed by the CPU 512. By the CPU 512 executing each control program stored in the ROM 513 under the management of the embedded OS stored in the ROM 513, software control such as scheduling and task switching is performed. The RAM 514 is composed of SRAM (Static RAM) or the like. The RAM 514 stores data such as program control variables, user-registered settings, and management data for the authentication server 500. The RAM 514 may also be used as a buffer for various work tasks. The image memory 515 is composed of memory such as DRAM (Dynamic RAM). The image memory 515 temporarily stores image data received via the communication unit 501 and image data read from the data storage unit 518 for processing by the CPU 512. The data storage unit 518 is composed of a storage medium such as an SSD (Solid State Drive) and continues to store data even when the authentication server 500 is powered off. In this embodiment, an SSD is given as an example of the data storage unit 518, but other storage media such as a hard disk or non-volatile memory may be used. The display unit 502 electronically controls the display content and performs control for displaying various input content and status information. The operation unit 503 receives user operations and performs control such as generating electrical signals corresponding to those operations and outputting them to the CPU 512.
[0041] The CPU 512 controls the communication control unit 517 to perform communication using the communication unit 501, and communicates data with other communication devices such as the access point 400. The communication unit 501 converts data into packets and sends the packets to other communication devices. The communication unit 501 also restores packets from other external communication devices back to their original data and outputs it to the CPU 512. The communication unit 501 is capable of data (packet) communication in a wired LAN (Ethernet) system compliant with, for example, the IEEE 802.3 series.
[0042] The following describes the communication modes in which the communication device in the communication system 100 can operate.
[0043] [Wireless Direct Mode] This document describes a communication method using wireless direct mode in WLAN communication, where devices communicate directly wirelessly without going through an external access point. Wireless direct mode communication can be implemented using multiple methods; for example, a communication device can selectively use one of the wireless direct modes described above to perform wireless direct mode communication. Wireless direct mode communication is sometimes referred to as "wireless direct communication" or "P2P communication."
[0044] For example, a communication device capable of performing wireless direct communication is configured to support at least one of two modes: soft AP mode and Wi-Fi Direct (WFD) mode. On the other hand, even a communication device capable of performing wireless direct communication does not have to support all of these modes; it may be configured to support only some of them. In this embodiment, the communication device can also support wireless infrastructure mode in addition to wireless direct mode.
[0045] A communication device (e.g., an information processing device 200) with WFD mode communication capabilities receives user input via its control panel, thereby calling an application to implement its communication function. Based on the user input received through the user interface screen provided by that application, it then performs communication in WFD mode. In P2P mode, the MFP300 acts as the master in connection and communication with other devices. However, this is not the case for WFD mode; the MFP300 may also act as a slave device by performing group owner negotiation.
[0046] [Wireless Infrastructure Mode] In contrast to wireless direct mode, wireless infrastructure mode connects communication devices that communicate with each other to an external access point that manages the network, and communication between communication devices takes place via the external access point. Here, "communication between communication devices" refers to, for example, the communication between the information processing device 200 and the MFP300. In other words, communication between communication devices is performed via the network established by the external access point. Furthermore, the MFP300 operating in wireless infrastructure mode acts as a slave device (station) in connection and communication with the access point 400. In wireless infrastructure mode, each communication device searches for an external access point by sending a device discovery request (ProbeRequest). When each communication device receives a device discovery response (ProbeResponse) from the external access point, it displays the SSID included in the ProbeResponse. For example, if the information processing device 200 and the MFP300 each discover access point 400 and send connection requests to this access point 400, communication between these communication devices in wireless infrastructure mode via access point 400 becomes possible. Note that multiple communication devices may connect to separate access points. In this case, data transfer between each access point enables communication between communication devices. The commands and parameters sent and received during communication between communication devices via the access points are those specified in the Wi-Fi standard. In the configuration described above, access point 400 determines the frequency band and frequency channel. Therefore, access point 400 selects which frequency band to use from 5GHz and 2.4GHz, and which frequency channel to use within that frequency band.
[0047] When the information processing device 200 or MFP300 connects to a wireless LAN configured by the access point 400, authentication is performed by the access point 400. The information processing device 200 and MFP300 can connect to the wireless LAN after being authenticated by the authentication method of the wireless LAN configured by the access point 400. Wireless LAN authentication methods include the PSK method using a pre-shared key, the SAE method using SAE, and the EAP method using an IEEE802.1X / EAP compliant authentication server.
[0048] [Wired communication mode] Wired communication mode is a communication mode for communication between communication devices via a wired LAN, etc. When the MFP300 is operating in wired communication mode, it cannot operate in wireless infrastructure mode. In wired communication mode, data (packet) communication is performed over a wired LAN (Ethernet) compliant with, for example, the IEEE 802.3 series. When the MFP300 is operating with IEEE 802.1X / EAP settings enabled, authentication by IEEE 802.1X is performed when connecting to a wired LAN configured by an access point 400.
[0049] [Simultaneous wireless operation] The MFP300 enables simultaneous (parallel) communication in two modes of communication when both modes use authentication methods that do not utilize the authentication server 500. In other words, it maintains the respective connections for each mode of communication simultaneously. Specifically, for example, it enables simultaneous communication using wireless infrastructure mode and communication using P2P mode. Therefore, the MFP300 simultaneously maintains both the connection for communication using wireless infrastructure mode and the connection for communication using P2P mode. This operation can also be described as "simultaneous wireless operation." In other words, simultaneous wireless operation means, for example, that the MFP300 simultaneously operates as a client device in Wi-Fi communication using wireless infrastructure mode and as a base station in Wi-Fi communication using P2P mode. On the other hand, when the MFP300 communicates using an authentication method that utilizes the authentication server 500, it does not simultaneously maintain both the infrastructure connection and the P2P connection.
[0050] Next, we will explain the power modes of the MFP300. The MFP300 has two power modes, for example, a normal power mode and a power-saving mode that consumes less power than the normal power mode. The MFP300 is configured to operate in multiple power modes, including these modes.
[0051] When the MFP300 is operating in normal power mode, power is supplied to, for example, the CPU 311, the print unit 316, the operation display unit 302, and the communication unit 322. As a result, when the MFP300 is operating in normal power mode, it can perform, for example, printing by the print unit 316, display processing and operation reception processing by the operation display unit 302, and communication processing by the communication unit 322. Also, when the MFP300 is operating in normal power mode, the CPU 311 operates at a predetermined operating frequency (referred to as the first operating frequency). Furthermore, if the communication unit 322 is configured to include a CPU 323 dedicated to the communication unit, the CPU 323 operates at a predetermined operating frequency (referred to as the second operating frequency). Note that the first and second operating frequencies may be the same or different. In this embodiment, the first operating frequency is assumed to be higher. Note that in order for each CPU to operate at a high operating frequency, each CPU needs to be supplied with a fast clock. Therefore, in this embodiment, a CPU operating at a higher operating frequency is assumed to be supplied with a faster clock.
[0052] When the MFP300 is operating in power-saving mode, power is supplied to the CPU 311 and the communication unit 322, for example. However, when the MFP300 is operating in power-saving mode, power is not supplied to a portion of the print unit 316 and a portion of the operation display unit 302, unlike in normal power mode. As a result, when the MFP300 is operating in power-saving mode, it is not possible to perform printing processing by the print unit 316 or display processing by the operation display unit 302, but it is possible to perform operation reception processing and communication processing by the communication unit 322. Also, when the MFP300 is operating in power-saving mode, the CPU 311 operates at a third operating frequency lower than the first operating frequency. Furthermore, if the communication unit 322 is configured to include a CPU 323 dedicated to the communication unit, when the MFP300 is operating in power-saving mode, the CPU 323 operates at a fourth operating frequency lower than the second operating frequency. The third and fourth operating frequencies may be the same or different. In this embodiment, the third operating frequency is assumed to be higher.
[0053] Note that the multiple power modes may include power modes other than those described above. For example, in this embodiment, a soft-off mode is included, which consumes even less power than the power-saving mode described above. When the MFP300 is operating in power-saving mode, power is supplied to the CPU311, but power is not supplied to the print unit 316, the communication unit 322, and part of the operation display unit 302. Therefore, when the MFP300 is operating in soft-off mode, the MFP300 cannot perform, for example, printing by the print unit 316, display processing and operation reception processing by the operation display unit 302 other than the power button 301, or communication processing by the communication unit 322. When the MFP300 is operating in soft-off mode and an operation is received via the power button 301, the MFP300 switches to normal power mode. Also, when the MFP300 is operating in normal power mode or power-saving mode and an operation is received via the power button 301, the MFP300 switches to soft-off mode. Furthermore, when the MFP300 is operating in soft-off mode, the CPU311 operates at a fifth operating frequency lower than the third operating frequency. Note that, for example, if the MFP300 has an automatic power-on function enabled, which automatically switches to normal power mode when a command is sent from the information processing device 200 via communication by the communication unit 322, then even when operating in soft-off mode, power may be supplied to the communication unit 322, enabling the communication unit 322 to perform communication processing.
[0054] Furthermore, the multiple power modes may include an intermediate mode in which power consumption is greater than that of the power-saving mode but less than that of the normal power mode. When the MFP300 is operating in intermediate mode, for example, power is supplied to the CPU311 and the communication unit322. However, when the MFP300 is operating in intermediate mode, unlike in normal power mode, power is not supplied to a part of the printing unit316 and a part of the operation display unit302. Also, when the MFP300 is operating in intermediate mode, the CPU311 operates at a seventh operating frequency that is lower than the first operating frequency and higher than the third operating frequency. Furthermore, if the communication unit322 is configured to include a CPU323 dedicated to the communication unit, when the MFP300 is operating in intermediate mode, the CPU323 operates at an eighth operating frequency that is lower than the second operating frequency and higher than the fourth operating frequency. Note that the intermediate mode is a mode used to prepare for the transition to power-saving mode, for example, when transitioning from normal power mode to power-saving mode, and the conditions for transitioning to intermediate mode are the same as the conditions for transitioning to power-saving mode. In other words, the MFP300 transitions from normal power mode to intermediate mode, and then from intermediate mode to power-saving mode. Thus, operation in other modes may occur in between the transition from normal power mode to power-saving mode.
[0055] The process for changing the power mode of the MFP300 in this embodiment will be explained with reference to Figure 14. When the power mode of the MFP300 is in normal power mode, the process from S1401 is executed. When the power mode of the MFP300 is in power saving mode, the process from S1403 is executed. The power mode control unit 325 in Figure 3 can control the switching of the power mode of the MFP300, and switches the power mode when the conditions for transitioning to a power mode are met. Although not shown in Figure 14, if the power button 301 is operated during the process in Figure 14, the system will transition to soft-off mode as described above. In other words, the condition for transitioning to soft-off mode is the operation of the power button 301.
[0056] In S1401, the power mode control unit 325 determines whether the state of the MFP 300 satisfies the conditions for transitioning to power saving mode. The process in S1401 is repeated until it is determined that the conditions for transitioning to power saving mode are met. The conditions for transitioning to power saving mode include, for example, that no user operations are received via the operation display unit 302 other than the power button 301 for a certain period of time. Alternatively, for example, no job acceptance is received via communication from the information processing device 200, etc., via the USB communication unit 308, wireless communication unit 307, wired communication unit 321, etc., for a certain period of time. If it is determined that the conditions for transitioning to power saving mode are met, in S1402, the power mode control unit 325 switches the power mode from normal power mode to power saving mode. When switching to power saving mode, the power mode control unit 325 reduces the operating frequency of the CPU 311 from the first operating frequency to the third operating frequency. Furthermore, if the communication unit 322 includes a CPU 323 dedicated to the communication unit, the power mode control unit 325 reduces the operating frequency of the CPU 323 from the second operating frequency to the fourth operating frequency.
[0057] In S1403, the power mode control unit 325 determines whether the state of the MFP 300 satisfies the conditions for transitioning to normal power mode. The process in S1403 is repeated until it is determined that the conditions for transitioning to normal power mode are met. The conditions for transitioning to normal power mode include, for example, the acceptance of an operation from the user via the operation display unit 302 other than the power button 301. It also includes, for example, the acceptance of a job via communication from the information processing device 200, etc., via the USB communication unit 308, wireless communication unit 307, wired communication unit 321, etc. If the conditions for transitioning to normal power mode are met, the operation control unit 319, USB communication control unit 320, and communication control unit 318 corresponding to the met transition conditions send a request to the power mode control unit 325 to change the power mode to normal power mode. Upon receiving the request, the power mode control unit 325 determines that the conditions for transitioning to normal power mode are met and proceeds to S1404.
[0058] In S1404, the power mode control unit 325 switches the power mode from power saving mode to normal power mode. When switching to normal power mode, the power mode control unit 325 also switches the operating frequency of the CPU 311 from the third operating frequency to the first operating frequency. Furthermore, if the communication unit 322 is configured to include a CPU 323 dedicated to the communication unit, the power mode control unit 325 switches the operating frequency of the CPU 323 from the fourth frequency to the second frequency.
[0059] Thus, in this embodiment, the CPU operating frequency is controlled when switching the power mode of the MFP300.
[0060] Next, we will describe the user interface screens displayed on the operation display unit 302 of the MFP300 and the display unit 202 of the information processing device 200, in order to connect the MFP300 to the network of the access point 400 using an authentication method with an authentication server 500.
[0061] Figure 11 is a diagram illustrating the screen transitions when LAN settings 343 is selected from the setting menu on screen 341 in Figure 4(b) on the operation display unit 302 of the MFP300. Screen 1100 shown in Figure 11(a) is displayed when "LAN settings" 342 is selected on screen 341 in Figure 4(b), and is a screen where the user can change the LAN settings. Screen 1110 shown in Figure 11(b) is displayed when "Wireless LAN" 1101 is selected on screen 1100 in Figure 11(a), and is a screen where the user can change the wireless LAN settings. Screen 1110 displays Wireless LAN Enable / Disable 1111, Wireless LAN Setup 1112, Wireless LAN Settings Display 1113, and Advanced Settings 1114. Wireless LAN Enable / Disable 1111 is an area for setting whether to enable or disable wireless LAN communication by the MFP300. On the display screen after the area in question is selected, user input is accepted, which sets the MFP300's wireless LAN communication capability to either disabled or enabled. When this capability is disabled, the MFP300 will not perform wireless LAN communication or connection.
[0062] The screen 1120 shown in Figure 11(c) is displayed when "Advanced Settings" 1114 is selected in the screen 1110 of Figure 11(b), and allows the user to change the LAN advanced settings. The screen 1130 shown in Figure 11(d) is displayed when "802.1X / EAP Settings" 1122 is selected in the screen 1120 of Figure 11(c), and allows the user to change the IEEE802.1X / EAP settings.
[0063] Screen 1140, shown in Figure 11(e), is displayed when IEEE802.1X / EAP settings are enabled, "Search for EAP routers" 1132 is selected on screen 1130, and a wireless access point search using the authentication server 500 is being performed. Wireless access point search is the process of searching for access points in the vicinity of the MFP300. Screen 1140, shown in Figure 11(e), is also displayed when "Wireless LAN setup" 1112 is selected on screen 1110 in Figure 11(b), and a wireless access point search using an authentication method that does not use the authentication server 500 is being performed.
[0064] The screen 1150 shown in Figure 11(f) displays a list of wireless access point identification names (SSID: Service Set Identifier) as a result of searching for wireless access points. If "EAP Router Search" 1132 is selected, an EAP router search is performed on the screen 1150 shown in Figure 11(f), and only the SSIDs of wireless access points using the IEEE802.1X / EAP authentication method are displayed. In this embodiment, since the access point is, for example, a router, the router search is equivalent to a wireless access point search. If "Wireless LAN Setup" 1112 is performed, only the SSIDs of wireless access points that do not use the IEEE802.1X / EAP authentication method are displayed.
[0065] The screen 1160 shown in Figure 11(g) is displayed while one of the wireless access point's SSIDs 1151, 1152, or 1153 is selected in the screen 1150 of Figure 11(f) and the connection process with the wireless access point is being performed. The screen 1170 shown in Figure 11(h) is displayed after the screen 1160 of Figure 11(g) is displayed, when the attempt to connect to the access point is completed and the connection is successful or the connection has progressed to a predetermined stage.
[0066] Screen 1180, shown in Figure 11(i), is the screen where "Enable / Disable IEEE802.1X / EAP" 1131 is selected in screen 1130 of Figure 11(d), allowing the user to change the IEEE802.1X / EAP setting between enabled and disabled. Screen 1180 displays both "Enable" 1151 and "Disable" 1152. When the IEEE802.1X / EAP setting is disabled, the MFP300 does not attempt to connect to an access point via IEEE802.1X / EAP. Screen 1190, shown in Figure 11(j), is the screen displayed when "Search for EAP routers" 1132 is selected in screen 1130 of Figure 11(d) when the IEEE802.1X / EAP setting is disabled. In other words, in this embodiment, even if "Search for EAP routers" 1132 is selected when the IEEE802.1X / EAP setting is disabled, the router search is not performed. The control performed when IEEE802.1X / EAP settings are disabled to prevent connection to access points using IEEE802.1X / EAP authentication is not limited to the control described above. For example, the MFP300 may perform a router search, but may not display access points with IEEE802.1X / EAP authentication enabled in the list of access points found by the router search. Alternatively, access points with IEEE802.1X / EAP authentication enabled may also be displayed in the list, but even if selected by the user, the MFP300 may not perform the connection process with access points with IEEE802.1X / EAP authentication enabled.
[0067] When connecting the MFP300 to a network where IEEE802.1X / EAP authentication is enabled, it is necessary to configure the MFP300 with the authentication information required before performing authentication. The outline of the process for connecting the MFP300 to a network where IEEE802.1X / EAP authentication is enabled, which is configured by the access point 400 in this embodiment, will be explained with reference to Figure 9.
[0068] First, in S901, a connection is established between the information processing device 200 and the MFP300 using a connection method that disables IEEE802.1X / EAP authentication. In S901, the information processing device 200 and the MFP300 are connected to a network that disables IEEE802.1X / EAP authentication, which is configured by an access point 400 as shown in Figure 10(b), enabling communication between the communication devices via the access point 400. A network that disables IEEE802.1X / EAP authentication is, for example, a network with an authentication method that does not use an authentication server 500. Alternatively, the connection between the information processing device 200 and the MFP300 may be achieved by connecting the information processing device 200 to a network configured by the MFP300 as a master station in wireless direct mode, as shown in Figure 10(c). Specifically, in S901, for example, the MFP300 receives a connection request from the information processing device 200 and establishes a connection between the MFP300, which operates in P2P mode, and the information processing device 200.
[0069] Next, in S902, as explained in Figure 12, the information processing device 200 transmits IEEE802.1X / EAP authentication information to the MFP300. The MFP300 then uses this information to perform the IEEE802.1X / EAP authentication settings. Then, in S903, as explained in Figure 13, the MFP300 connects to the IEEE802.1X / EAP authentication enabled network configured by the access point 400. In other words, the MFP300 establishes a connection with an access point that enables IEEE802.1X / EAP authentication. In S903, the MFP300 is connected to the IEEE802.1X / EAP authentication enabled network (for example, using an authentication server 500) configured by the access point 400 as shown in Figure 10(a), and communication devices can communicate with each other via the access point 400.
[0070] Figure 12 is a diagram illustrating the screen transitions in the information processing device 200. Figure 12(a) shows an example of the settings screen of the MFP300 displayed on the information processing device 200. The screen 1200 in Figure 12(a) is displayed when a web browser or application running on the information processing device 200 communicates with an HTTP server running on the MFP300. Alternatively, the screen 1200 shown in Figure 12(a) may be displayed by the USB communication control unit 320 of the MFP300 waiting for and responding to HTTP requests via USB communication.
[0071] If "Security Settings" 1204 is selected on screen 1200 in Figure 12(a), screen 1210 shown in Figure 12(b) will be displayed. If "IEEE802.1X / EAP Settings" 1212 is selected on screen 1210 in Figure 12(b), screen 1220 shown in Figure 12(c) will be displayed.
[0072] If "Authentication Method" 1221 is selected on screen 1220 in Figure 12(c), screen 1230 shown in Figure 12(d) will be displayed. On screen 1230 in Figure 12(d), selecting either "EAP-TLS" 1231, "EAP-TTLS" 1232, or "PEAP" 1233 will set the authentication method to be used for IEEE802.1X / EAP authentication on the MFP300. Also, if a login name is entered in "Username" 1234 and a password in "Password" 1235 on screen 1230 in Figure 12(d), the login name and password to be used for IEEE802.1X / EAP authentication will be set on the MFP300.
[0073] On screen 1220 in Figure 12(c), the user selects "Key and Certificate Settings" 1222, and on screen 1240 in Figure 12(e), the user selects "Upload Key and Certificate" 1241, which displays screen 1250 in Figure 12(f). On screen 1250, the user can register the certificate to be used for IEEE802.1X / EAP authentication to the MFP300. On screen 1250 in Figure 12(f), the user selects a file using "Select File" 1251, thereby selecting the certificate to be used for IEEE802.1X / EAP authentication. Then, on screen 1250, the user enters a password in "Password" 1252 and selects "Upload" 1253, setting the certificate and password to be used for IEEE802.1X / EAP authentication to the MFP300.
[0074] On screen 1240 in Figure 12(e), the user can delete the certificate stored on the MFP300 by selecting "Delete keys and certificates" 1242. Additionally, on screen 1240 in Figure 12(e), the user can view a list of certificates stored on the MFP300 by selecting "View keys and certificates" 1243.
[0075] When the user selects "Enable / Disable IEEE802.1X / EAP" 1223 on screen 1220 in Figure 12(c), screen 1260 shown in Figure 12(g) is displayed. On screen 1260 in Figure 12(g), the user can enable or disable IEEE802.1X / EAP on the MFP300.
[0076] Through the user operations described above, the user can configure authentication information used for IEEE 802.1X / EAP authentication for the MFP300. The MFP300 is authenticated by the authentication server 500 using the configured authentication information, and can then connect to the network using the authentication server 500, which is configured with access points 400.
[0077] Here, if the MFP300 can enable multiple communication modes simultaneously (in parallel), specifically if it can maintain both wireless infrastructure mode and P2P mode connections in parallel, then even if the infrastructure connection side is connected to a network using the authentication server 500, the device can be connected on the P2P connection side. In that case, it is possible for devices not authenticated by the authentication server 500 to request changes to the MFP300's settings or print requests. When the MFP300 connects to a network using the authentication server 500 on the infrastructure connection side, it is preferable that devices not authenticated by the authentication server 500 do not perform changes to the MFP300's settings or print requests, without being aware of the order in which the communication modes are switched.
[0078] The following describes the IEEE 802.1X / EAP settings of the MFP300 and the process of dynamically switching the communication mode according to the authentication method of the wireless infrastructure mode. This process improves the convenience of setting the communication mode.
[0079] Figure 13 is a flowchart illustrating the setup process for connecting the MFP300 to a network using an authentication server 500 configured with access points 400. Before performing the setup process shown in Figure 13, it is necessary to configure the MFP300 with authentication information used for IEEE 802.1X / EAP authentication using S902 in Figure 9. If authentication information is not configured in the MFP300, EAP authentication will fail. The process shown in Figure 13 is achieved, for example, by the CPU 311 reading and executing a program stored in program memory 313.
[0080] In S1301, the CPU 311 of the MFP300 receives an access point search request. For example, when the user selects "Search for EAP router" 1132 on screen 1130 in Figure 11(d), the CPU 311 receives an access point search request.
[0081] In S1302, the CPU 311 determines whether the access point search request is for an Enterprise access point. In other words, S1302 determines whether the access point is for an authentication method that uses the authentication server 500. Hereinafter, access points for authentication methods that use the authentication server 500 will also be referred to as Enterprise access points. On the other hand, access points for authentication methods that do not use the authentication server 500, such as authentication methods that use shared keys, will also be referred to as Personal access points. If the user selects "Search for EAP router" 1132 on screen 1130 in Figure 11(d), the CPU 311 determines that it is for an Enterprise access point. On the other hand, if the user selects "Wireless LAN setup" 1112 on screen 1110 in Figure 11(b), the CPU 311 determines that it is not for an Enterprise access point. Alternatively, the determination in S1302 may be made based on whether the search request received by the MFP 300 via the communication path includes an instruction to search for an Enterprise access point. If the access point search request in S1302 is determined to be an access point search for Enterprise, the process proceeds to S1303. On the other hand, if the access point search request is determined not to be an access point search for Enterprise, the process proceeds to S1307.
[0082] In S1303, the CPU 311 determines whether the IEEE802.1X / EAP setting is enabled or disabled. The determination in S1303 is based, for example, on the setting of "Enable / Disable IEEE802.1X / EAP" 1131 on screen 1130 in Figure 11(d). If it is determined in S1303 that the IEEE802.1X / EAP setting is enabled, the process proceeds to S1305. If it is determined that the IEEE802.1X / EAP setting is disabled, the process proceeds to S1304. In S1304, the CPU 311 responds that the search for Enterprise access points cannot be performed, and then terminates the process shown in Figure 13. For example, if the IEEE802.1X / EAP setting is disabled and "Search for EAP routers" 1132 is selected on screen 1130 in Figure 11(d), then in S1304, a screen like the one shown on screen 1190 in Figure 11(j) will be displayed. In S1305, the CPU 311 searches for access points using the authentication method with the authentication server 500, and in S1306, it stores that it has performed a search for access points using the authentication method with the authentication server 500.
[0083] If in S1302 the access point search request is determined not to be for an Enterprise access point, then in S1307 the CPU 311 performs a search for a Personal access point. Then, in S1308 the CPU 311 stores that it has performed a search for a Personal access point. After S1306 and S1308, the process proceeds to S1309.
[0084] In S1309, the CPU 311 displays a list of wireless access point SSIDs as a result of the access point search, as shown in screen 1150 of Figure 11(f). In S1310, the CPU 311 accepts the user's selection of the SSID of the access point to connect to.
[0085] In S1311, the CPU 311 determines whether the wireless direct mode is enabled or disabled. In this embodiment, the enabled (ON) / disabled (OFF) state of each communication mode is stored as setting information in the MFP 300, so the determination in S1311 is made, for example, based on the stored information for each communication mode. If it is determined that the wireless direct mode is enabled, the process proceeds to S1312; if it is determined that the wireless direct mode is disabled, the process proceeds to S1316.
[0086] In S1312, the CPU 311 determines whether the IEEE802.1X / EAP setting is enabled or disabled. The determination in S1312 is made, for example, based on the setting of "Enable / Disable IEEE802.1X / EAP" 1131 on screen 1130 in Figure 11(d). If it is determined that the IEEE802.1X / EAP setting is enabled, the process proceeds to S1313; if it is determined that the IEEE802.1X / EAP setting is disabled, the process proceeds to S1316.
[0087] In S1313, the CPU 311 determines whether the access point to be connected to is an access point that uses an authentication method with an authentication server 500. If it is determined that it is an access point that uses an authentication method with an authentication server 500, the process proceeds to S1314; if it is determined that it is not an access point that uses an authentication method with an authentication server 500, the process proceeds to S1316. The determination in S1313 is made, for example, based on the contents stored in S1306 and S1308.
[0088] In S1314, the CPU 311 disables the wireless direct mode. Then, in S1315, the CPU 311 enables the wireless infrastructure mode and connects to a network using an authentication method that utilizes an authentication server 500 configured by the access point 400, using the authentication information set in S902. Specifically, disabling the wireless direct mode means that, for example, the MFP 300 stops operating as an access point or as a Wi-Fi Direct group owner, and does not establish direct Wi-Fi connections with other devices.
[0089] From S1311 onwards, if wireless direct mode is enabled, IEEE802.1 / EAP settings are enabled, and the access point to be connected uses an authentication method that utilizes the authentication server 500, wireless direct mode is disabled and wireless infrastructure mode is enabled. When wireless infrastructure mode is enabled, the MFP300 connects to the access point 400 using the authentication information set by the information processing device 200. Note that enabling wireless infrastructure mode means starting operation in wireless infrastructure mode.
[0090] On the other hand, if it is determined that any of the conditions in S1311, S1312, or S1313 are not met, in S1316, the CPU 311 enables wireless infrastructure mode and connects the MFP 300 to the access point 400. However, in this case, the connection using wireless infrastructure mode will be a communication connection that does not use the IEEE802.1X / EAP authentication method. Also, if it is determined that the conditions are not met in S1312 or in S1313, both wireless infrastructure mode without the IEEE802.1X / EAP authentication method and wireless direct mode will be enabled. Note that if the access point's SSID is selected in S1310 and the process proceeds to S1315, screen 1160 in Figure 11(g) will be displayed until the access point connection attempt starts in S1315. Furthermore, if the process proceeds to S1316, screen 1160 in Figure 11(g) will be displayed until success or failure to access the access point is determined in S1316.
[0091] As described above, the MFP300 can be connected to a network using an authentication method that utilizes an authentication server 500 composed of access points 400.
[0092] Next, we will explain the process of appropriately switching the MFP300 power mode when connecting to a wireless network using an authentication method that utilizes the authentication server 500.
[0093] Figure 15 is a flowchart showing the process of changing the operating frequency of the MFP300 when the MFP300 attempts to connect to the access point 400. The process in Figure 15 is implemented, for example, by the CPU 311 reading and executing a program stored in the program memory 313. The process in Figure 15 is executed when the communication mode of the MFP300 is wireless infrastructure mode and when connecting to the access point 400. Connecting to the access point 400 includes reconnecting after communication with the access point 400 has been lost. For example, the process in Figure 15 is started when the MFP300 is operating in power-saving mode, and the target access point has been identified, but it is not connected to that access point, and a wireless access point search is being performed to find the target access point (hereinafter referred to as the identified state).
[0094] First, let's explain the effects of executing the process shown in Figure 15. For example, after being instructed to connect to access point 400 in S1310, the MFP300 performs a wireless access point search to find access point 400 in order to connect to the target access point, access point 400. However, if the MFP300 performs a wireless access point search while access point 400 is powered off, the MFP300 will not be able to find access point 400. In other words, the MFP300 will remain unable to connect to access point 400 for a certain period of time and will switch to power-saving mode. In this embodiment, this state corresponds to a specific state. Subsequently, when the power to access point 400 is turned on, access point 400 will be found by the wireless access point search, but at that time the MFP300 will be operating in power-saving mode. In other words, in this case, the MFP300 will attempt to connect to access point 400 while remaining in power-saving mode.
[0095] Furthermore, while operating in normal power mode, the MFP300 and access point 400 are connected, but then the MFP300 switches to power-saving mode, and the connection between the MFP300 and access point 400 may be lost. In that case, in order to reconnect with the access point 400, which is the access point to be connected to, the MFP300 performs a wireless access point search to find access point 400. In this embodiment, this state also corresponds to a specific state. If access point 400 is found in that search, the MFP300 will attempt to connect to access point 400 while still in power-saving mode. Incidentally, when the MFP300 attempts to connect to access point 400, authentication by the authentication server 400 may be required. However, when the operating frequency of the MFP300 is reduced due to power-saving mode, if the encryption key length of the public key algorithm used for EAP authentication using the authentication server 500 is long, authentication by access point 400 may take a long time, and the authentication may time out. In other words, if the MFP300 attempts to connect to the access point 400 while in power-saving mode, it may fail to connect to the access point 400.
[0096] Therefore, in this embodiment, under specific conditions, the power mode of the MFP300 is changed according to the communication mode of the MFP300 and the authentication method used for connection with the access point, and the operating frequency is dynamically changed. With such a configuration, the time required for authentication can be shortened and authentication timeouts can be prevented. In the case of MFPs with embedded processors with limited processing performance, or MFPs in which the processor's operating frequency can be selectively changed from several operating frequency stages rather than continuously, the possibility of the above-mentioned timeout is expected to increase, so the effect of this embodiment becomes even more pronounced.
[0097] In S1501, the CPU 311 determines whether it is possible to perform authentication with access point 400 after the access point 400 to be connected to has been found through the wireless access point search. If it is determined that it is possible to perform authentication with access point 400, the process proceeds to S1502. If it is determined that it is not possible to perform authentication with access point 400, the wireless access point search continues and this determination is repeated until it becomes possible to perform authentication with access point 400.
[0098] In S1502, the CPU 311 determines whether the IEEE802.1X / EAP setting of the MFP300 is enabled or disabled. The determination in S1502 may be made, for example, based on the setting of "Enable / Disable IEEE802.1X / EAP" 1131 on screen 1130 in Figure 11(d). If it is determined that the IEEE802.1X / EAP setting is enabled, the process proceeds to S1503; if it is determined that the IEEE802.1X / EAP setting is disabled, the process proceeds to S1507.
[0099] In S1503, the CPU 311 determines whether the authentication method for the wireless infrastructure mode is an authentication method that uses the authentication server 500. In other words, this determination determines whether the executed wireless access point search is a search for access points that correspond to an authentication method that uses the authentication server 500, or a search for access points that correspond to an authentication method that does not use the authentication server 500. The determination in S1503 may be made, for example, based on the contents stored in S1306 and S1308. If it is determined that it is an authentication method that uses the authentication server 500, the process proceeds to S1504; if it is determined that it is not an authentication method that uses the authentication server 500, the process proceeds to S1507. Note that an authentication method that uses the authentication server 500 is the IEEE802.1X / EAP authentication method, and an authentication method that does not use the authentication server 500 is an authentication method that is not IEEE802.1X / EAP.
[0100] In S1504, CPU311 determines whether the IEEE802.1X / EAP authentication method is EAP-TLS or EAP-TTLS, or neither EAP-TLS nor EAP-TTLS. The determination in S1504 may be made, for example, based on the settings configured on screen 1230 in Figure 12(d). If it is determined to be EAP-TLS or EAP-TTLS, the process proceeds to S1505; if it is determined to be neither EAP-TLS nor EAP-TTLS, the process proceeds to S1507. Note that neither EAP-TLS nor EAP-TTLS means that it is PEAP. This process is executed because the authentication processing load for EAP-TLS or EAP-TTLS is generally greater than that for PEAP.
[0101] In S1505, CPU311 determines whether the encryption key length used in the public key algorithm used for IEEE802.1X / EAP authentication is greater than or equal to a first threshold. If it is determined that the encryption key length is greater than or equal to the first threshold, the process proceeds to S1506; otherwise, it proceeds to S1507. For example, 1024 bits can be set as the first threshold. If 1024 bits is set as the first threshold, for example, if an RSA encryption method with an encryption key length of 1024 bits or 2048 bits is used as the public key algorithm, the process proceeds to S1506. On the other hand, if an ECC (Elliptic Curve Cryptography) encryption method with an encryption key length of 256 bits is used as the public key algorithm, the process proceeds to S1507.
[0102] In S1506, if the power mode of the MFP300 is in power-saving mode, the communication control unit 318 sends a request to the power mode control unit 325 to switch the power mode from power-saving mode to normal power mode. The power mode control unit 325 then changes the power mode to normal power mode and changes the operating frequencies of the CPU 311, communication control unit 318, and communication unit 322 to the operating frequencies of normal power mode. After S1506, in S1507, the CPU 311 performs the connection process to the access point 400. During the connection process to the access point 400, authentication is performed by the access point 400. If it is determined that none of the conditions in S1502 to S1505 are met, the connection process to the access point 400 is performed in S1507 while operating in power-saving mode, without changing the operating frequency (i.e., transitioning to normal power mode).
[0103] As described above, according to this embodiment, the MFP300 can dynamically change its operating frequency when connecting to an access point 400 that uses an authentication method with an authentication server 500. Specifically, the MFP300 controls whether to return the power mode to normal power mode depending on whether the executed wireless access point search is for an access point corresponding to an authentication method using an authentication server 500 or an access point corresponding to an authentication method that does not use an authentication server 500. More specifically, the MFP300 controls whether to return the power mode to normal power mode depending on whether the authentication method using the authentication server 500 is EAP-TLS or EAP-TTLS. More specifically, the MFP300 controls whether to return the power mode to normal power mode depending on whether the algorithm of the public key used in the authentication method using the authentication server 500 is above a threshold.
[0104] In Figure 15, four conditions S1502, S1503, S1504, and S1505 are checked as conditions for transitioning from power-saving mode to normal power mode, but it is not necessary to check all of the conditions. For example, it is possible to check only one of the above conditions, or for example, to check only S1502 and S1503 as conditions for transitioning from power-saving mode to normal power mode, and not check S1504 and S1505. In that case, if S1503 is checked as YES, the process proceeds to S1506. Alternatively, the transition from power-saving mode to normal power mode may be controlled by checking other factors. For example, the check in S1503 may determine whether the access point to be connected is an access point that supports an authentication method using the authentication server 500. Furthermore, if it is determined that the access point is compatible with the authentication method using the authentication server 500, it may be controlled to switch from power-saving mode to normal power mode, and if it is not compatible with the authentication method using the authentication server 500, it may be controlled not to switch from power-saving mode to normal power mode.
[0105] [Second Embodiment] The second embodiment will now be described in terms of its differences from the first embodiment. In the first embodiment, a configuration was described in which the power mode of the MFP300 is appropriately switched when the MFP300 is connected to an access point 400 using an authentication method with an authentication server 500. In this embodiment, a configuration will be described in which the power mode of the MFP300 is appropriately switched when authentication by the authenticator is initiated.
[0106] In the communication system 100 of this embodiment, an authentication device 400 (authenticater) is used instead of the access point 400 in Figure 1, and the authentication server 500 is a Radius server. That is, the authentication device 400 includes not only a router but also an L2 switch, a hub, and the like.
[0107] Figure 16 is a flowchart showing the process of changing the operating frequency of the MFP300 when the MFP300 attempts to connect to the authentication device 400. The process in Figure 16 is implemented, for example, by the CPU 311 reading and executing a program stored in the program memory 313. The process in Figure 16 is executed when the MFP300's communication mode is either wireless infrastructure mode or wired communication mode, and when connecting to the authentication device 400. Connecting to the authentication device 400 includes reconnecting after communication with the authentication device 400 has been disconnected. For example, the process in Figure 16 is started when the MFP300 is operating in power-saving mode, and the target access point has been identified, but it is not connected to that access point, and a wireless access point search is being performed to find the target access point.
[0108] In S1601, the CPU 311 determines whether or not it is possible to perform authentication processing with the authentication device 400. The determination of whether or not it is possible to perform authentication processing may be made, for example, based on the fact that the MFP 300 has requested a device discovery request and received a device discovery response from the authentication device 400, if the communication mode of the MFP 300 is wireless infrastructure mode. Alternatively, if the communication mode of the MFP 300 is wired communication mode, the determination may be made based on the fact that communication has become possible because the MFP 300 and the authentication device 400 are connected by a LAN cable. If it is determined that it is possible to perform authentication processing with the authentication device 400, the process proceeds to S1602. If it is determined that it is not possible to perform authentication processing with the authentication device 400, this determination is repeated until it becomes possible to perform authentication processing with the authentication device 400.
[0109] Sections S1602 to S1604 are the same as those in sections S1502 to S1505, so their explanations will be omitted.
[0110] In S1605, the CPU 311 determines whether the communication mode of the MFP 300 is wireless infrastructure mode and whether the encryption key length used in the public key algorithm used for IEEE 802.1X / EAP authentication is greater than or equal to a first threshold. If it is determined that the encryption key length is greater than or equal to the first threshold, the process proceeds to S1606; otherwise, the process proceeds to S1608.
[0111] In S1608, the CPU 311 determines whether the communication mode of the MFP 300 is wired infrastructure mode and whether the encryption key length used in the public key algorithm used for IEEE 802.1X / EAP authentication is greater than or equal to a second threshold, which is greater than or equal to a first threshold. If it is determined that the encryption key length is greater than or equal to the second threshold, the process proceeds to S1606; otherwise, the process proceeds to S1607.
[0112] For example, a first threshold of 1024 bits is set. If a first threshold of 1024 bits is set, and for example an RSA encryption method with a key length of 1024 bits or 2048 bits is used as the public key algorithm, the process proceeds to S1606. On the other hand, if, for example an ECC encryption method with a key length of 256 bits is used as the public key algorithm, the process proceeds to S1607. For example, a second threshold of 4096 bits is set. If a second threshold of 4096 bits is set, and for example an RSA encryption method with a key length of 4096 bits is used as the public key algorithm, the process proceeds to S1606. On the other hand, if, for example an RSA encryption method with a key length of 1024 bits or 2048 bits is used as the public key algorithm, the process proceeds to S1607.
[0113] In S1606, if the power mode of the MFP300 is in power-saving mode, the communication control unit 318 sends a request to the power mode control unit 325 to switch the power mode from power-saving mode to normal power mode. The power mode control unit 325 then changes the power mode to normal power mode and changes the operating frequencies of the CPU 311, communication control unit 318, and communication unit 322 to the operating frequencies of normal power mode. After S1606, in S1607, the authentication process by the authentication device 400 is performed. If it is determined that none of the conditions in S1602-S1604 or S1608 are met, the authentication process by the authentication device 400 is performed in S1607 while the device is operating in power-saving mode, without changing the operating frequency (i.e., switching to normal power mode).
[0114] As described above, according to this embodiment, the MFP300 can dynamically change its operating frequency when authentication is initiated by the authentication device 400 using the authentication method with the Radius server 500.
[0115] In Figure 16, four conditions S1602, S1603, S1604, and S1605 are checked as conditions for transitioning from power-saving mode to normal power mode. However, it is not necessary to check all of these conditions. For example, it is possible to check only one of the above conditions. For instance, as a condition for transitioning from power-saving mode to normal power mode, only checks S1602 and S1603 may be performed, while checks S1604 and S1605 may not be performed. In that case, if S1603 is checked as YES, the process proceeds to S1606. Alternatively, the decision to transition from power-saving mode to normal power mode may be controlled by checking other factors.
[0116] The present invention can also be realized by supplying a program that implements one or more of the functions of the above-described embodiments to a system or device via a network or storage medium, and by having one or more processors in the computer of that system or device read and execute the program. It can also be realized by a circuit (e.g., an ASIC) that implements one or more functions.
[0117] The invention is not limited to the embodiments described above, and various modifications and variations are possible without departing from the spirit and scope of the invention. Accordingly, claims are attached to disclose the scope of the invention. [Explanation of symbols]
[0118] 100 Communication Systems: 200 Information Processing Devices: 300 MFPs: 400 Access Points: 500 Authentication Servers
Claims
1. A communication device, In a state in which the communication device is operating in a first state in which the processor of the communication device is operating at a first operating frequency, when a process for connecting the communication device with a first external device corresponding to an authentication process using a first authentication method with an authentication server is started, the state of the communication device is transitioned to a second state in which the processor of the communication device is operating at a second operating frequency higher than the first operating frequency. Control means for controlling the communication device to perform authentication using the first authentication method via the first external device while the communication device is operating in the second state described above. It has, The control means controls the communication device to perform authentication using the second authentication method via the second external device without transitioning the state of the communication device to the second state, based on the fact that a process for connecting the communication device to a second external device corresponding to an authentication process using a second authentication method different from the first authentication method is initiated while the communication device is operating in the first state. A communication device characterized by the following features.
2. The communication device according to claim 1, characterized in that the first state is a state in which power is supplied to a first number of units provided in the communication device, and the second state is a state in which power is supplied to a second number of units provided in the communication device that is greater than the first number.
3. The communication device according to claim 1 or 2, characterized in that the first state is a state in which a first clock is supplied to the processor of the communication device, and the second state is a state in which a second clock that is faster than the first clock is supplied to the processor of the communication device.
4. The communication device according to any one of claims 1 to 3, characterized in that the first state is a state in which power is not supplied to the printed circuit board of the communication device, and the second state is a state in which power is supplied to the printed circuit board of the communication device.
5. The communication device according to any one of claims 1 to 4, characterized in that the authentication process by the first authentication method is an authentication process compliant with the IEEE 802.1X standard.
6. The communication device according to claim 5, characterized in that the authentication process by the second authentication method is an authentication process compliant with the IEEE 802.1X standard.
7. The first authentication method is the EAP-TLS (EAP-Transport Layer Security) method or the EAP-TTLS (EAP-Tunneled TLS) method. The communication device according to any one of claims 1 to 6, characterized in that the second authentication method is the PEAP (Protected EAP) method.
8. The communication device according to any one of claims 1 to 6, characterized in that the second authentication method is an authentication method that does not use the authentication server.
9. The control means is In the state in which the communication device is operating, based on the commencement of a connection process between the first external device and the communication device, which corresponds to an authentication process using an encryption key of a first length according to the first authentication method, the processor of the communication device is transitioned to a second state operating at the second operating frequency. The communication device according to any one of claims 1 to 8, characterized in that, while the communication device is operating in the first state, the communication device controls the system to perform authentication using the first authentication method via the third external device without transitioning the state of the communication device to the second state, based on the fact that a process for connecting the communication device to a third external device corresponding to an authentication process using an encryption key of a second length shorter than the first length according to the first authentication method is initiated.
10. A communication device, In a state in which the communication device is operating in a first state in which the processor of the communication device is operating at a first operating frequency, based on the commencement of a connection process between the communication device and a first external device corresponding to an authentication process using an encryption key of a first length by a first authentication method using an authentication server, the state of the communication device is transitioned to a second state in which the processor of the communication device is operating at a second operating frequency higher than the first operating frequency. In the state in which the communication device is operating as described in the second state, a control means controls the authentication using the first authentication method to be performed via the first external device, It has, The control means controls the communication device to perform authentication using the first authentication method via the third external device without transitioning the state of the communication device to the second state, based on the fact that a process for connecting the communication device to a third external device corresponding to an authentication process using an encryption key of a second length shorter than the first length according to the first authentication method is initiated while the communication device is operating in the first state. A communication device characterized by the following features.
11. The first length encryption key is a 1024-bit or 2048-bit encryption key, The communication device according to claim 9 or 10, characterized in that the second length encryption key is a 256-bit encryption key.
12. The authentication process using the first encryption key of the first length according to the first authentication method is an authentication process that uses the RSA encryption scheme as the public key algorithm. The communication device according to any one of claims 9 to 11, wherein the authentication process using the second length encryption key according to the first authentication method is an authentication process that uses ECC (Elliptic Curve Cryptography) encryption as the public key algorithm.
13. In the first state described above, the communication device further includes a search means for wirelessly searching for an external device to which it was wirelessly connected, The communication device according to any one of claims 1 to 9, characterized in that the first external device and the second external device are external devices discovered by the search means.
14. The communication device according to any one of claims 1 to 9, characterized in that the first external device and the second external device are access points or authenticators.
15. The control means is In the state in which the communication device is operating, based on the commencement of processing for wireless connection between the first external device and the communication device, which corresponds to authentication processing using an encryption key of the first length according to the first authentication method, the processor of the communication device is switched to a second state operating at the second operating frequency. In the state in which the communication device is operating, based on the fact that a process for wireless connection between the third external device and the communication device is initiated, corresponding to an authentication process using an encryption key of a second length shorter than the first length according to the first authentication method, authentication according to the first authentication method is performed via the third external device without transitioning the state of the communication device to the second state. In the state in which the communication device is operating in the first state, based on the commencement of processing for a wired connection between the communication device and a fourth external device corresponding to an authentication process using an encryption key of a third length longer than the first length according to the first authentication method, the processor of the communication device is switched to a second state operating at the second operating frequency. In the state in which the communication device is operating as described above, based on the commencement of processing for a wired connection between the communication device and a fifth external device corresponding to an authentication process using an encryption key of a fourth length shorter than the third length according to the first authentication method, authentication according to the first authentication method is performed via the fifth external device without transitioning the state of the communication device to the second state. A communication device according to any one of claims 9 to 11, characterized by the features described herein.
16. The third length encryption key is a 4096-bit encryption key, The communication device according to claim 15, characterized in that the fourth length encryption key is a 1024-bit or 2048-bit encryption key.
17. The communication device according to claim 15 or 16, characterized in that the operating frequency of the processor of the communication device is selectively changed from several operating frequencies.
18. The communication device according to any one of claims 1 to 17, further comprising at least one of a printing means for performing printing and a scanning means for performing scanning.
19. A method for controlling a communication device, A transition step is performed to transition the state of the communication device to a second state in which the processor of the communication device operates at a second operating frequency higher than the first operating frequency, based on the commencement of a connection process between the communication device and a first external device corresponding to an authentication process using a first authentication method with an authentication server, while the communication device is operating in a first state in which the processor of the communication device operates at a first operating frequency, the processor of the communication device is operating at a second operating frequency higher than the first operating frequency, the processor of the communication device is operating at a second operating frequency higher than the first operating frequency, the processor of the communication device is operating at a first state in which the processor of the communication device operates In the state in which the communication device is operating, an authentication step is performed by performing authentication using the first authentication method via the first external device, It has, A control method characterized in that, while the communication device is operating in the first state, the state of the communication device is not transitioned to the second state based on the commencement of a connection process between the communication device and an external device corresponding to an authentication process using a second authentication method different from the first authentication method, and authentication using the second authentication method is performed via the first external device while the communication device is operating in the first state.
20. A method for controlling a communication device, In a state in which the communication device is operating in a first state in which the processor of the communication device is operating at a first operating frequency, based on the commencement of a connection process between the communication device and a first external device corresponding to an authentication process using an encryption key of a first length by a first authentication method using an authentication server, the state of the communication device is transitioned to a second state in which the processor of the communication device is operating at a second operating frequency higher than the first operating frequency. A control step in which, while the communication device is operating in the second state, the device is controlled to perform authentication using the first authentication method via the first external device. It has, In the control step, while the communication device is operating in the first state, based on the fact that a process for connecting the communication device to a third external device corresponding to an authentication process using an encryption key of a second length shorter than the first length according to the first authentication method is initiated, the control is performed to execute authentication according to the first authentication method via the third external device without transitioning the state of the communication device to the second state. A control method characterized by the following:
21. A communication device, A search means for searching for a first external device that corresponds to authentication processing using a first authentication method that uses an authentication server, A transition means is provided to transition the state of the communication device to a second state in which the processor of the communication device operates at a second operating frequency higher than the first operating frequency, based on the fact that a search is performed by the search means while the communication device is operating in a first state in which the processor of the communication device operates at a first operating frequency, and that processing for connection between the first external device discovered by the search and the communication device is started, In the state in which the communication device is operating as described in the second state, control means for controlling the authentication using the first authentication method to be performed via the first external device. A communication device characterized by having the following features.
22. A method for controlling a communication device, A search step to search for a first external device that corresponds to authentication processing using a first authentication method that uses an authentication server, A transition step is performed to transition the state of the communication device to a second state in which the processor of the communication device operates at a second operating frequency higher than the first operating frequency, based on the fact that the search in the search step is performed while the communication device is operating in a first state in which the processor of the communication device operates at a first operating frequency, and that the process for connecting the first external device discovered by the search and the communication device is started, A control step in which, while the communication device is operating in the second state, the device is controlled to perform authentication using the first authentication method via the first external device. A control method characterized by having the following features.
23. A program for causing a computer to function as one of the means of a communication device described in any one of claims 1 to 18 or 21.
24. A computer-readable storage medium storing a program for causing a computer to function as one of the means of a communication device described in any one of claims 1 to 18 or 21.
Citation Information
Patent Citations
Data communication apparatus, data communication method, data converter, and conversion selection method
JP2005117232A
Communication apparatus, method of controlling the same, and program
JP2010226657A
Communication method and communication system
JP2011176469A
Information processing apparatus and method of controlling the same, and program
JP2013161409A
Information processing device, control method of information processing device, and program
JP2014106835A