First communication device and computer program for the first communication device

By determining its role based on connection status, the first communication device optimally transmits or receives configuration information, addressing inefficiencies in existing wireless connection methods and ensuring seamless communication.

JP7838619B2Active Publication Date: 2026-04-01BROTHER KOGYO KK
View PDF 5 Cites 0 Cited by

Patent Information

Authority / Receiving Office
JP · JP
Patent Type
Patents
Current Assignee / Owner
Filing Date
2024-11-27
Publication Date
2026-04-01

AI Technical Summary

Technical Problem

Existing wireless communication methods, such as the Device Provisioning Protocol (DPP) established by the Wi-Fi Alliance, do not adequately consider the role and situation of the first communication device, leading to inefficiencies in establishing wireless connections.

Method used

The first communication device determines its role based on whether a wireless connection is established with an access point, assuming a first role to transmit configuration information or a second role to receive configuration information, enabling it to establish appropriate wireless connections accordingly.

Benefits of technology

This approach allows the first communication device to efficiently establish wireless connections by assuming the appropriate role, ensuring seamless communication with either an access point or another device, thereby simplifying the connection process.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure 0007838619000001
    Figure 0007838619000001
  • Figure 0007838619000002
    Figure 0007838619000002
  • Figure 0007838619000003
    Figure 0007838619000003
Patent Text Reader

Abstract

To provide techniques to enable a first communication device to play an appropriate role considering the situation thereof.SOLUTION: A first communication device performs output control processing for outputting output information obtained by using a public key of the first communication device to the outside, and receives an authentication request in which the public key is used from a second communication device that has obtained the public key. If a radio connection is established between the first communication device and a first access point, the first communication device transmits, to the second communication device, a first authentication response including first role information indicating that the first communication device plays a first role. If no radio connection is established between the first communication device and any access point, the first communication device transmits, to the second communication device, a second authentication response including second role information indicating that the first communication device plays a second role different from the first role.SELECTED DRAWING: Figure 7
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This specification discloses a technique for establishing a wireless connection between a first communication device and another device.

Background Art

[0002] Non-Patent Document 1 describes the DPP (abbreviation for Device Provisioning Protocol) method, a wireless communication method established by the Wi-Fi Alliance. The DPP method is a wireless communication method for easily establishing a Wi-Fi connection between a pair of devices. In the DPP method, a first device playing the role of a Configurator transmits information for establishing a Wi-Fi connection to a second device playing the role of an Enrollee. Then, a Wi-Fi connection is established between the second device and another device (which may be, for example, the first device or a device different from the first device).

Prior Art Documents

Non-Patent Documents

[0003]

Non-Patent Document 1

Summary of the Invention

Problems to be Solved by the Invention

[0004] This specification provides a technique in which a first communication device can play an appropriate role in consideration of the situation of the first communication device itself.

Means for Solving the Problems

[0005] The first communication device disclosed herein includes a wireless interface for performing wireless communication in accordance with the Wi-Fi standard, an output control unit that performs output control processing for outputting output information in accordance with the Wi-Fi standard, which is obtained using the public key of the first communication device, to the outside, an authentication request receiving unit that receives an authentication request using the public key from a second communication device that has acquired the public key via the wireless interface, a first determination unit that determines whether or not a wireless connection has been established between the first communication device and any access point, and a first authentication response transmitting unit that, when the authentication request has been received from the second communication device and it is determined that a wireless connection has been established between the first communication device and the first access point, transmits a first authentication response to the second communication device via the wireless interface, which includes first role information indicating that the first communication device assumes a first role, wherein the first role is to send first wireless configuration information to the second communication device for the second communication device to establish a first wireless connection with the first access point. The first authentication response transmission unit, which has the role of transmitting, the first wireless configuration transmission unit, which transmits the first wireless configuration information to the second communication device via the wireless interface after the first authentication response has been transmitted to the second communication device, and the second authentication response transmission unit, which, when the authentication request has been received from the second communication device and it is determined that a wireless connection has not been established between the first communication device and any access point, transmits a second authentication response to the second communication device via the wireless interface, which includes a second role information indicating that the first communication device assumes a second role different from the first role, wherein the second role is to receive a second wireless configuration information from the second communication device for the first communication device to establish a second wireless connection with the second access point, the second authentication response transmission unit, which receives the second wireless configuration information from the second communication device via the wireless interface after the second authentication response has been transmitted to the second communication device, and uses the second wireless configuration information via the wireless interface,It may also include a first establishment unit for establishing the second wireless connection with the second access point.

[0006] According to the above configuration, the first communication device determines whether or not a wireless connection has been established between the first communication device and any access point. When a wireless connection has been established between the first communication device and the first access point, the first communication device assumes a first role, which is to transmit the first wireless configuration information to the second communication device, and transmits the first wireless configuration information to the second communication device. As a result, the first wireless connection can be established between the second communication device and the first access point. Furthermore, when a wireless connection has not been established between the first communication device and any access point, the first communication device assumes a second role, which is to receive the second wireless configuration information from the second communication device, and receives the second wireless configuration information from the second communication device. As a result, the second wireless connection can be established between the first communication device and the second access point. Therefore, the first communication device can assume an appropriate role, taking into account its own situation.

[0007] A control method, computer program, and computer-readable recording medium for realizing the first communication device described above are also novel and useful. Furthermore, a communication system comprising the above communication device and other devices (e.g., a second communication device, an external device) is also novel and useful. [Brief explanation of the drawing]

[0008] [Figure 1] This shows the configuration of the communication system. [Figure 2] This diagram shows a schematic sequence of steps for establishing a wireless connection between a printer and an access point according to the DPP (Digital Printing Protocol) method. [Figure 3] This shows the sequence diagram of the bootstrapping process. [Figure 4] This shows a sequence diagram of the authentication process. [Figure 5] The sequence diagram for the Configuration process is shown. [Figure 6] This shows the sequence diagram for Network Access processing. [Figure 7] This shows a flowchart of the authentication process. [Figure 8] This diagram shows the sequence of bootstrapping and authentication processes in Case A, where a wireless connection is established between the printer and the access point (AP). [Figure 9] The sequence diagram continues from Figure 8, showing the Configuration process and the Network Access process. [Figure 10] This diagram shows the sequence of bootstrapping and authentication processes in Case B, where wireless connections are established between the printer and the AP, and between the terminal device and the AP. [Figure 11] The sequence diagram continues from Figure 10, showing the Configuration process and the Network Access process. [Figure 12] This diagram shows the sequence of bootstrapping processes in Case C, where a wireless connection is established between the printer and the access point (AP) according to the WFD method. [Figure 13] The sequence diagram (Authentication process) following Figure 12 is shown. [Figure 14] The sequence diagram (Configuration processing) following Figure 13 is shown. [Figure 15] The sequence diagram (Network Access processing) continues from Figure 14. [Figure 16] A table summarizing each case in this embodiment is shown. [Modes for carrying out the invention]

[0009] (Examples) (Configuration of communication system 2; Figure 1) As shown in FIG. 1, the communication system 2 includes two access points (hereinafter simply referred to as "APs") 6 and 8, a printer 10, and two terminals 100 and 200. In this embodiment, for example, the user uses the terminal 100 to establish a wireless connection (hereinafter referred to as "Wi-Fi connection") conforming to the Wi-Fi standard between the printer 10 and the AP 6.

[0010] (Configuration of Terminal 100) The terminal 100 is a portable terminal device such as a mobile phone (e.g., a smartphone), a PDA, or a tablet PC. In a modified example, the terminal 100 may be a stationary terminal device. The terminal 100 includes a camera 115 and a Wi-Fi interface 116. Hereinafter, the interface will be simply referred to as "I / F".

[0011] The camera 115 is a device for photographing an object, and in this embodiment, it is used to photograph the QR code (registered trademark) for each of the APs 6 and 8 and the printer 10.

[0012] The Wi-Fi I / F 116 is a wireless interface for performing communication conforming to the Wi-Fi standard. The Wi-Fi standard is a standard for performing wireless communication, for example, according to the 802.11 standard of IEEE (abbreviation of The Institute of Electrical and Electronics Engineers, Inc.) and the standards conforming thereto (e.g., 802.11a, 11b, 11g, 11n, etc.). The Wi-Fi I / F 116 supports the DPP (abbreviation of Device Provisioning Protocol) method formulated by the Wi-Fi Alliance. The DPP method is described in the standard document "Device Provisioning Protocol Technical Specification Version 1.1" created by the Wi-Fi Alliance, and it is a method for easily establishing a Wi-Fi connection between a pair of devices (e.g., the printer 10 and the AP 6) using the terminal 100.

[0013] The Wi-Fi I / F 116 further supports the WFD (abbreviation for Wi-Fi Direct (registered trademark)) method established by the Wi-Fi Alliance. The WFD method is described in the standard document "Wi-Fi Peer-to-Peer (P2P) Technical Specification Version 1.1" created by the Wi-Fi Alliance. In WFD, a Group Owner state (hereinafter referred to as the "G / O state") and a Client state (hereinafter referred to as the "CL state") are defined. Also, in this embodiment, a state different from both the G / O state and the CL state is referred to as the "device state". A device that supports the WFD method can selectively operate in one of the above three states. Hereinafter, a Wi-Fi connection established according to the WFD method may be described as a "WFD connection".

[0014] (Configuration of Terminal 200) The terminal 200 is also a portable terminal device similar to the terminal 100. In a modified example, the terminal 200 may be a stationary terminal device. The terminal 200 also includes a camera 215 and a Wi-Fi I / F 216, similar to the terminal 100.

[0015] (Configuration of Printer 10) The printer 10 is a peripheral device capable of executing a printing function (for example, a peripheral device of terminals 100 and 200). The printer 10 includes an operation unit 12, a display unit 14, a Wi-Fi I / F 16, a printing execution unit 18, and a control unit 30. Each unit 12 to 30 is connected by a bus line (reference numerals omitted).

[0016] The operation unit 12 includes a plurality of buttons. The user can input various instructions to the printer 10 by operating the operation unit 12. The display unit 14 is a display for displaying various information. The display unit 14 further functions as a so-called touch panel (i.e., an operation unit). The printing execution unit 18 includes a printing mechanism such as an inkjet method or a laser method.

[0017] The Wi-Fi interface 16 supports both DPP and WFD methods. Therefore, the printer 10 can establish a Wi-Fi connection with AP6, and furthermore, it can establish a WFD connection with a terminal (e.g., terminal 100) without going through the AP. In the following, the Wi-Fi connection with AP6 may be referred to as "AP connection."

[0018] The Wi-Fi I / F16 is assigned two MAC addresses: "mac_ap" and "mac_wfd". MAC address "mac_ap" is used for AP (Access Point) connections. MAC address "mac_wfd" is used for WFD (Wireless Flow) connections.

[0019] The control unit 30 comprises a CPU 32 and a memory 34. The CPU 32 performs various processes according to the program 40 stored in the memory 34. The memory 34 is composed of volatile memory, non-volatile memory, etc.

[0020] Furthermore, the memory 34 can store AP information 44 used to establish an AP connection.

[0021] (DPP overview; Figure 2) Next, with reference to Figure 2, the outline of DPP will be explained. AP6 also supports the DPP method. In this embodiment, each device 6, 10, and 100 performs communication according to the DPP method, thereby establishing a DPP connection between the printer 10 and AP6. In the following, for ease of understanding, the operations performed by the CPU of each device (e.g., CPU 32) will be described from the perspective of each device (e.g., printer 10) rather than from the perspective of the CPU.

[0022] In T5, terminal 100 performs DPP-based bootstrapping (hereinafter simply referred to as "BS") with AP6. This BS is a process in which AP6 provides information to terminal 100 that will be used in the Authentication (hereinafter simply referred to as "Auth") of T10 described later, in response to the QR code attached to AP6 being photographed by the camera 115 of terminal 100.

[0023] In T10, terminal 100 uses the information obtained from T5's BS to perform DPP authentication with AP6. This authentication is a process in which both terminal 100 and AP6 authenticate their respective communication partners.

[0024] In T15, terminal 100 performs a DPP-based configuration (hereinafter simply referred to as "Config") with AP6. This Config is a process that sends information to AP6 for AP6 to establish an AP connection according to the DPP method. Specifically, terminal 100 generates an AP Configuration Object (hereinafter simply referred to as "CO") and sends the AP CO to AP6. As a result, AP6 stores the AP CO.

[0025] Next, terminal 100 executes a DPP-based BS (Blockchain System) with printer 10 in T25. This BS is a process in which, in response to the QR code displayed on printer 10 being photographed by terminal 100's camera 115, information to be used in the authentication of T30 (described later) is provided from printer 10 to terminal 100.

[0026] In T30, terminal 100 uses the information obtained in T25's BS to perform DPP-based authentication with printer 10. This authentication is a process for both terminal 100 and printer 10 to authenticate their communication partners.

[0027] In T35, terminal 100 executes a DPP-based configuration with printer 10. This configuration is a process that sends information to printer 10 to establish a DPP connection between printer 10 and AP6. In this configuration, terminal 100 generates a first printer CO to establish an AP connection between printer 10 and AP6 according to the DPP method, and sends the first printer CO to printer 10. As a result, the first printer CO is stored in printer 10.

[0028] In T40, printer 10 and AP6 perform DPP-based Network Access (hereinafter simply referred to as "NA") using the stored AP CO and the first printer CO. NA is a process for sharing a connection key between printer 10 and AP6 to establish an AP connection according to the DPP method. Subsequently, printer 10 and AP6 perform a 4-way handshake. During at least part of the 4-way handshake communication, printer 10 and AP6 communicate encrypted information encrypted with the shared connection key. If the decryption of the encrypted information is successful, an AP connection is established between printer 10 and AP6. This allows printer 10 to participate as a slave station in the wireless network formed by AP6. In a modified version, printer 10 and AP6 may perform SAE (Simultaneous Authentication of Equals, commonly known as "Dragonfly") communication instead of 4-way handshake communication.

[0029] In the DPP method, the user does not need to input information about the wireless network in which AP6 acts as the master station (e.g., SSID, password, etc.) into the printer 10 in order to establish an AP connection between the printer 10 and AP6. Therefore, the user can easily establish an AP connection between the printer 10 and AP6.

[0030] (Details of each process; Figures 3-6) Next, referring to Figures 3 to 6, the details of each process performed at T25 to T40 in Figure 2 will be explained. Note that the processes at T5 to T15 are the same as those at T25 to T35, except that AP6 is used instead of printer 10, so a detailed explanation of them will be omitted.

[0031] (Bootstrapping (BS); Figure 3) First, referring to Figure 3, we will explain the BS process performed at T25 in Figure 2. In the initial state of Figure 3, the printer 10's memory 34 already stores the printer 10's public key PPK1 and private key psk1. Also, in the initial state of Figure 3, memory 34 does not store the AP information 44.

[0032] In T100, the user operates the control unit 12 to input a predetermined instruction to the printer 10. When the printer 10 receives the predetermined instruction from the user in T100, it displays a selection screen on the display unit 14 in T102. The selection screen is for selecting a communication method. The selection screen includes an "AP communication" button indicating the use of communication via AP, and a "WFD communication" button indicating the use of communication according to the WFD method without using AP. Note that the selection screen does not have to be displayed. In this case, for example, when the user gives instructions on the first screen regarding the use of communication via AP, an AP QR code (see T106) may be displayed, and when the user gives instructions on a second screen, which is different from the first screen and is a second screen regarding the use of communication according to WFD, a WFD QR code (see T856 in Figure 12) may be displayed.

[0033] In T104, the user operates the control unit 12 to select the "AP Communication" button on the selection screen. When the printer 10 receives the user's selection of the "AP Communication" button in T104, it displays the AP QR code on the display unit 14 in T106. The AP QR code is obtained by encoding the printer 10's public key PPK1 and the MAC address "mac_ap" used for AP connection.

[0034] In response to user input, terminal 100 activates its camera 115, and at T120, uses camera 115 to capture the AP QR code displayed on T100. Then, at T122, terminal 100 decodes the captured AP QR code to obtain the public key PPK1 and the MAC address "mac_ap". Once processing at T122 is complete, the process shown in Figure 3 is finished.

[0035] (Authentication (Auth); Figure 4) Next, referring to Figure 4, the authentication process performed at T30 in Figure 2 will be explained. Note that all of the following communications between terminal 100 and printer 10 are performed via the Wi-Fi interface 116 of terminal 100 and the Wi-Fi interface 16 of printer 10. Therefore, the phrase "via Wi-Fi interface 116 (or 16)" will be omitted below.

[0036] At T200, terminal 100 generates its public key TPK1 and private key tsk1. Next, at T202, terminal 100 generates a shared key SK1 using the generated private key tsk1 and the public key PPK1 of printer 10 obtained at T122 in Figure 3, according to ECDH (Elliptic curve Diffie-Hellman key exchange). Then, at T204, terminal 100 encrypts a random value RV1 using the generated shared key SK1 to generate encrypted data ED1.

[0037] In T210, terminal 100 sends a DPP Authentication Request (hereinafter simply referred to as "AReq") to printer 10, with the MAC address "mac_ap" obtained in T122 in Figure 3 as the destination. AReq is a signal requesting printer 10 to perform authentication. AReq includes terminal 100's public key TPK1 generated in T200, encrypted data ED1 generated in T204, terminal 100's capability, and the MAC address "mac_ap".

[0038] Capability is pre-specified information for devices that support the DPP method, and includes one of the following values: a value indicating that it can operate only as a DPP Configurator, a value indicating that it can operate only as a DPP Enrollee, or a value indicating that it can operate as either a Configurator or an Enrollee. A Configurator is responsible for sending the CO used in the NA (e.g., T35 in Figure 2) to the Enrollee in Config (e.g., T40 in Figure 2). On the other hand, an Enrollee is responsible for receiving the CO used in the NA from the Configurator in Config. In this case, AReq includes a value indicating that terminal 100 can operate as either a Configurator or an Enrollee as part of its capability.

[0039] Printer 10 receives AReq from terminal 100 at T210. As described above, AReq is sent to the MAC address "mac_ap" of printer 10's Wi-Fi I / F 16 as the destination. Therefore, printer 10 can properly receive AReq from terminal 100.

[0040] When printer 10 receives an AReq from terminal 100 at T210, it executes the process shown in Figure 7 (described later) at T211 to determine printer 10's capability as Enrollee.

[0041] Next, the printer 10 performs a process to authenticate the source of the AReq (i.e., terminal 100). Specifically, at T212, the printer 10 generates a shared key SK1 in accordance with ECDH, using the public key TPK1 of terminal 100 in the AReq and the private key psk1 of the printer 10. Here, the shared key SK1 generated by terminal 100 at T202 and the shared key SK1 generated by the printer 10 at T212 are the same. Therefore, at T214, the printer 10 can properly decrypt the encrypted data ED1 in the AReq using the generated shared key SK1, and as a result, obtain the random value RV1. If the decryption of the encrypted data ED1 is successful, the printer 10 determines that the source of the AReq is the device that photographed the QR code displayed at T100 in Figure 3, that is, it determines that authentication has been successful, and executes the processes from T216 onwards. On the other hand, if the decryption of the encrypted data ED1 is unsuccessful, the printer 10 will determine that the source of the AReq is not the device that photographed the QR code displayed by T100, that is, that authentication has failed, and will not execute the processes from T216 onward.

[0042] At T216, printer 10 generates a new public key PPK2 and a new private key psk2. In the modified version, printer 10 may have the public key PPK2 and private key psk2 stored in advance. Next, at T217, printer 10 generates a shared key SK2 according to ECDH, using the public key TPK1 of terminal 100 in AReq at T210 and the generated private key psk2 of printer 10. Then, at T218, printer 10 uses the generated shared key SK2 to encrypt the acquired random value RV1 and the new random value RV2 to generate encrypted data ED2.

[0043] In T220, printer 10 sends a DPP Authentication Response (hereinafter simply referred to as "ARes") to terminal 100. This ARes includes the printer 10's public key PPK2 generated in T216, the encrypted data ED2 generated in T218, and the printer 10's capability determined in T211 (i.e., a value indicating that it can operate only as an Enrollee).

[0044] Terminal 100 receives ARes from printer 10 at T220. In this case, terminal 100 performs a process to authenticate the source of the ARes (i.e., printer 10). Specifically, at T222, terminal 100 generates a shared key SK2 according to ECDH, using terminal 100's private key tsk1 generated at T200 and printer 10's public key PPK2 in the ARes. Here, the shared key SK2 generated by printer 10 at T217 and the shared key SK2 generated by terminal 100 at T222 are the same. Therefore, at T224, terminal 100 can properly decrypt the encrypted data ED2 in the ARes using the generated shared key SK2, and as a result, obtain the random values ​​RV1 and RV2. If the decryption of the encrypted data ED2 is successful, terminal 100 determines that the source of the ARes is the device that has the scanned QR code, that is, determines that authentication has been successful, and performs the process from T230 onwards. On the other hand, if the decryption of the encrypted data ED2 is unsuccessful, terminal 100 will determine that the source of the ARes is not a device possessing the scanned QR code, that is, that authentication has failed, and will not execute the processes from T230 onward.

[0045] At T230, terminal 100 sends a Confirm to printer 10. The Confirm includes information indicating that terminal 100 will act as a Configurator and printer 10 will act as an Enrollee. As a result, at T232, terminal 100 decides to act as a Configurator, and at T234, printer 10 decides to act as an Enrollee. Once processing at T234 is complete, the process shown in Figure 4 is completed.

[0046] (Configuration(Config); Figure 5) Next, referring to Figure 5, the Config process performed at T35 in Figure 2 will be explained. At T300, printer 10 sends a DPP Configuration Request (hereinafter simply referred to as "CReq") to terminal 100. CReq is a signal requesting the transmission of the first printer CO. CReq includes the value "sta," which indicates that printer 10 has received the first printer CO. Furthermore, CReq includes the value "config," which requests operational information for printer 10 to operate as a Configurator. For example, consider Case A (Figures 8 and 9), described later, where communication according to the DPP method is performed between printer 10 and terminal 100 after the processes in Figures 3 to 6 have been completed and an AP connection has been established between printer 10 and AP6. In this case, printer 10 operates as a Configurator, uses the first printer CO to generate the first terminal CO, and sends the first terminal CO to terminal 100. In this case, prior to the later case A, printer 10 sends a CReq containing the value "config" to terminal 100 in T300. This allows printer 10 to act as a Configurator in the later case A and generate a first terminal CO using the first printer CO obtained from terminal 100.

[0047] When terminal 100 receives a CReq from printer 10 at T300, at T302, it retrieves the group ID "Group1", the public key TPK2, and the private key tsk2 from terminal 100's memory (not shown). As described above, terminal 100 has already executed the Config at T15 in Figure 2 with AP6, and at this time, it generates and stores the group ID "Group1", the public key TPK2, and the private key tsk2 in memory. The group ID "Group1" is information that identifies the wireless network formed when a Wi-Fi connection is established between printer 10 and AP6. In the modified example, a string specified by the user may be used as the group ID. That is, at T302, terminal 100 retrieves the information stored at T15 in Figure 2. Next, at T304, terminal 100 generates the first printer CO. Specifically, terminal 100 executes the following processes.

[0048] Terminal 100 first generates a hash value HV1 by hashing its public key TPK2. Terminal 100 then generates a specific value by hashing a combination of the hash value HV1, the group ID "Group1", and the public key PPK2 of printer 10 in the ARes of T220 in Figure 4. Then, terminal 100 generates an electronic signature DSpr1 by encrypting the generated specific value using terminal 100's private key tsk2, according to the ECDSA (Elliptic Curve Digital Signature Algorithm). As a result, terminal 100 can generate a first printer Signed-Connector (hereinafter, Signed-Connector will simply be referred to as "SC") which includes the hash value HV1, the group ID "Group1", the public key PPK2 of printer 10, and the electronic signature DSpr1. Then, terminal 100 generates a first printer CO which includes a first printer SC and terminal 100's public key TPK2.

[0049] In T310, terminal 100 sends a DPP Configuration Response (hereinafter simply referred to as "CRes") containing a first printer CO to printer 10. Here, CRes contains operational information as a response to the value "config" in CReq. The operational information includes information (e.g., terminal 100's private key tsk2) for printer 10 to act as a Configurator and generate a first terminal CO for another terminal (e.g., terminal 200).

[0050] When printer 10 receives CRes from terminal 100 at T310, it stores the first printer CO within CRes at T312. The first printer CO is information used to establish an AP connection with AP6, and can be described as connection information for establishing an AP connection with AP6. Printer 10 stores the first printer CO as AP information 44. When processing at T312 is completed, the process shown in Figure 5 is completed.

[0051] (Network Access (NA); Figure 6) Next, referring to Figure 6, the processing of NA at T40 in Figure 2 will be explained. As described above, the processing of T5 to T15 has already been executed between terminal 100 and AP6, similar to T25 to T35 in Figure 2. AP6 has its public key APK1 and private key ask1 stored in advance. A QR code obtained by encoding AP6's public key APK1 and AP6's MAC address is attached to the AP6's casing. When terminal 100 scans this QR code, the same processing as that from T200 onwards in Figure 4 is executed between terminal 100 and AP6. As a result, AP6 stores AP6's public key APK2 and private key ask2 (see T216 in Figure 4), and also stores the AP CO received from terminal 100 (see T312 in Figure 5). The AP CO includes the AP SC and terminal 100's public key TPK2. The public key TPK2 is the same as the public key TPK2 included in the first printer CO. The AP SC includes the hash value HV1, the group ID "Group1", the AP6 public key APK2, and the digital signature DSap1. The hash value HV1 and the group ID "Group1" are the same as the hash value HV1 and group ID "Group1" included in the first printer CO, respectively. The digital signature DSap1 is information encrypted by the terminal 100's private key tsk2, obtained by hashing the combination of the hash value HV1, group ID "Group1", and public key APK2, and is a different value from the digital signature DSpr1 included in the first printer CO.

[0052] Printer 10 sends a DPP Peer Discovery Request (hereinafter simply referred to as "DReq") containing the first printer SC to AP6 on T400. DReq is a signal requesting AP6 to perform authentication and send the AP SC.

[0053] When AP6 receives a DReq from printer 10 at T400, it performs a process to authenticate the source of the DReq (i.e., printer 10) and each piece of information within the DReq (i.e., hash value HV1, "Group1", and public key PPK2). Specifically, at T402, AP6 first performs a first AP determination process to determine whether the hash value HV1 and group ID "Group1" in the received first printer SC match the hash value HV1 and group ID "Group1" in the AP SC contained in the stored AP CO. In the case of Figure 6, AP6 determines in the first AP determination process that they match, and therefore determines that the authentication of the source of the DReq (i.e., printer 10) has been successful. Note that the fact that the hash value HV1 in the received first printer SC matches the hash value HV1 in the AP SC contained in the stored AP CO means that the first printer SC and the AP SC were generated by the same device (i.e., terminal 100). Therefore, AP6 also determines that the authentication of the origin of the first printer SC that has been received (i.e., terminal 100) has been successful.

[0054] AP6 further uses the public key TPK2 of terminal 100, which is included in the stored AP CO, to decrypt the digital signature DSpr1 in the received first printer SC. In the case of Figure 6, the decryption of the digital signature DSpr1 is successful, so AP6 performs a second AP decision process to determine whether the specific value obtained by decrypting the digital signature DSpr1 matches the value obtained by hashing each piece of information in the received first printer SC (i.e., hash value HV1, "Group1", and public key PPK2). In the case of Figure 6, AP6 determines in the second AP decision process that they match, so it determines that the authentication of each piece of information in DReq has been successful and performs the processes from T404 onwards. The determination in the second AP decision process that they match means that each piece of information in the received first printer SC (i.e., hash value HV1, "Group1", and public key PPK2) has not been tampered with by a third party after the first printer CO was stored in the printer 10. On the other hand, if the first AP judgment process determines that there is no match, if the decryption of the digital signature DSpr1 fails, or if the second AP judgment process determines that there is no match, AP6 determines that authentication has failed and does not execute the processes from T404 onward.

[0055] Next, AP6 generates a connection key (i.e., a shared key) CK1 in T404 according to ECDH, using the acquired printer 10's public key PPK2 and AP6's stored private key ask2.

[0056] In the T410, AP6 sends a DPP Peer Discovery Response (hereinafter simply referred to as "DRes"), which includes an SC for AP, to printer 10.

[0057] When printer 10 receives DRes from AP6 at T410, it performs a process to authenticate the source of the DRes (i.e., AP6) and each piece of information within the DRes (i.e., hash value HV1, "Group1", and public key APK2). Specifically, at T412, printer 10 first performs a first PR (Public Relations) determination process to determine whether the hash value HV1 and group ID "Group1" in the received AP SC match the hash value HV1 and group ID "Group1" in the first printer SC contained in the stored first printer CO. In the case of Figure 6, printer 10 determines in the first PR determination process that they match, and therefore determines that the authentication of the source of the DRes (i.e., AP6) has been successful. Furthermore, if the hash value HV1 in the received AP SC matches the hash value HV1 in the first printer SC contained in the stored first printer CO, it means that the first printer SC and the AP SC were generated by the same device (i.e., terminal 100). Therefore, printer 10 also determines that the authentication of the source of the received AP SC (i.e., terminal 100) was successful.

[0058] Printer 10 further decrypts the digital signature DSap1 in the received AP SC using the public key TPK2 of terminal 100, which is included in the stored first printer CO. In the case of Figure 6, the decryption of the digital signature DSap1 is successful, so printer 10 performs a second PR decision process to determine whether the specific value obtained by decrypting the digital signature DSap1 matches the value obtained by hashing each piece of information in the received AP SC (i.e., hash value HV1, "Group1", and public key APK2). In the case of Figure 6, printer 10 determines that they match in the second PR decision process, so it determines that the authentication of each piece of information in DRes has been successful and performs the processes from T414 onwards. The determination that they match in the second PR decision process means that each piece of information in the AP SC (i.e., hash value HV1, "Group1", and public key APK2) has not been tampered with by a third party after the AP CO was stored in AP6. On the other hand, if the first PR judgment process determines that there is no match, if the decryption of the electronic signature DSap1 fails, or if the second PR judgment process determines that there is no match, the printer 10 determines that authentication has failed and does not execute the processes from T414 onward.

[0059] At T414, printer 10 generates a connection key CK1 according to ECDH, using the stored printer 10 private key psk2 and the received AP6 public key APK2 in the AP SC. Here, the connection key CK1 generated by AP6 at T404 and the connection key CK1 generated by printer 10 at T414 are the same. As a result, the connection key CK1 for establishing the AP connection is shared between printer 10 and AP6.

[0060] As described above, after the connection key CK1 is shared between printer 10 and AP6, T420 uses the connection key CK1 to perform a 4-way handshake communication between printer 10 and AP6. As a result, an AP connection is established between printer 10 and AP6. When T420 terminates, the process shown in Figure 6 ends.

[0061] (Authentication process for printer 10; Figure 7) Referring to Figure 7, the authentication process implemented by the CPU 32 of the printer 10 will be explained. Of the authentication processes in Figure 4, the process executed by the printer 10 is implemented by the process in Figure 7.

[0062] In S2, CPU32 monitors for the reception of AReq from the terminal that scanned the QR code on printer 10 (hereinafter referred to as the "Initiator terminal") via Wi-FiI / F16 during BS processing. If CPU32 receives AReq from the Initiator terminal (YES in S2), it proceeds to S4. The processing of T210 in Figure 4 is implemented by the processing in S2. Note that all communication in the processing of Figure 7 is performed via Wi-FiI / F16. Therefore, the phrase "via Wi-FiI / F16" will be omitted below.

[0063] In S4, CPU32 determines whether the received AReq contains the MAC address "mac_ap". As shown in T106 in Figure 3, if the "AP Communication" button is selected, an AP QR code containing information including the MAC address "mac_ap" is displayed. The Initiator terminal then scans the AP QR code, obtains the MAC address "mac_ap", and sends the AReq containing the MAC address "mac_ap" to the printer 10. On the other hand, if the "WFD Communication" button is selected on the selection screen, a WFD QR code containing information including the MAC address "mac_wfd", which is used for WFD connections, is displayed. The Initiator terminal then scans the WFD QR code, obtains the MAC address "mac_wfd", and sends the AReq containing the MAC address "mac_wfd" to the printer 10. CPU32 proceeds to S10 if it determines that the received AReq contains the MAC address "mac_ap" (YES in S4), and to S20 if it determines that the received AReq contains the MAC address "mac_wfd" (NO in S4). Then, printer 10 establishes an AP connection with one of the APs if it determines that the AReq contains the MAC address "mac_ap" (YES in S4), and establishes a WFD connection with the Initiator terminal if it determines that the AReq contains the MAC address "mac_wfd". The process of establishing a WFD connection will be described later in Figures 12 to 15. With this configuration, printer 10 can establish an appropriate Wi-Fi connection depending on the MAC address contained in the AReq.

[0064] In S10, the CPU 32 determines whether or not the AP information 44 is stored in memory 34. If the AP information 44 is not stored in memory 34, it means that an AP connection has not been established between the printer 10 and any AP. If the CPU 32 determines that the AP information 44 is not stored in memory 34 (NO in S10), it proceeds to S16.

[0065] In S16, CPU32 determines the capability of printer10 to "Enrollee".

[0066] Next, in S40, CPU32 performs the same processing as T212~T218 in Figure 4 (i.e., authentication of the Initiator terminal and generation of encrypted data).

[0067] Next, in S42, CPU32 sends ARes containing the capability "Enrollee" to the Initiator terminal.

[0068] Next, in S44, CPU32 performs a Confirm process similar to T230 and T234 in Figure 4. That is, CPU32 decides to act as an Enrollee. When the process in S44 is completed, the process in Figure 7 is completed.

[0069] Furthermore, the fact that AP information 44 is stored in memory 34 means that an AP connection has been established between the printer 10 and one of the APs (for example, AP6). If the CPU 32 determines that AP information 44 is stored in memory 34 (YES in S10), it proceeds to S12.

[0070] In S12, the CPU 32 determines whether the AReq received in S2 contains a value indicating that the Initiator terminal is capable of operating only as an Enrollee. Situations in which the received AReq contains a value indicating that it is capable of operating only as an Enrollee include, for example, a situation where a program is installed on the Initiator terminal that prioritizes receiving COs from other devices, or a situation where the user has performed an operation to select receiving COs from other devices on the Initiator terminal. If the CPU 32 determines that the received AReq contains a value indicating that it is capable of operating only as an Enrollee (YES in S12), the process proceeds to S14.

[0071] In S14, CPU32 determines the capability of printer 10 to "Configurator". The following S30 is the same as S40.

[0072] Next, in S32, CPU32 sends an ARes containing the capability "Configurator" to the Initiator terminal.

[0073] Next, in S34, CPU32 executes the Confirm process. In the Confirm process in S34, unlike the Confirm process executed in S44, CPU32 decides to act as a Configurator. When the process in S34 is completed, the process shown in Figure 7 is completed.

[0074] Furthermore, if the CPU 32 determines that the received AReq contains a value indicating that it can operate as either a Configurator or an Enrollee, or if it determines that the received AReq contains a value indicating that it can operate only as a Configurator (NO in S12), it proceeds to S16. That is, the CPU 32 determines the capability of the printer 10 to be "Enrollee". Then, the processes in S40 to S44 are executed, and the process shown in Figure 7 is completed.

[0075] Furthermore, if CPU32 determines that the received AReq contains the MAC address "mac_wfd" (NO in S4), it executes the processes in S20 to S26. Printer 10 performs the G / O Negotiation described later to select either the G / O state or the CL state. If, as a result of the G / O Negotiation, printer 10 is in the G / O state (YES in S20), CPU32 proceeds to S24; if, as a result of the G / O Negotiation, printer 10 is in the CL state (NO in S20), it proceeds to S26.

[0076] In S24, CPU32 determines the capability of printer 10 to "Configurator". Then, after S24 finishes, CPU32 executes processes S30 to S34 and finishes the process shown in Figure 7.

[0077] In S26, the CPU 32 determines the capability of printer 10 to "Enrollee". Then, after S26 is completed, the CPU 32 executes the processes in S40 to S44 and finishes the process shown in Figure 7.

[0078] For example, consider a comparative example in which the decision in S10 (i.e., whether or not AP information 44 is stored) is performed before AReq is received from the Initiator terminal. For example, printer 10 performs the decision in S10 during BS processing before Auth processing. In this comparative example, printer 10 unnecessarily performs the decision in S10 even if Auth processing is not performed for some reason (e.g., communication failure). In contrast, according to the configuration of this embodiment, printer 10 performs the decision in S10 only when AReq is received from the Initiator terminal (YES in S2). According to the configuration of this embodiment, it is possible to suppress the unnecessary execution of the decision in S10. Note that in modified examples, the configuration of the comparative example may be adopted.

[0079] (Specific Case A; Figures 8 and 9) Referring to Figures 8 and 9, we will explain a specific case A realized by the process in Figure 7. Case A is a continuation of the process in Figure 2 (i.e., Figures 3 to 6). That is, in the initial state of Case A, an AP connection is established between the printer 10 and AP6. For this reason, the first printer CO is stored in the printer 10's memory 34 as AP information 44 (see T312 in Figure 5). Also, terminal 200 has not established an AP connection with any AP. In this case, after establishing an AP connection between the printer 10 and AP6, an AP connection is established between terminal 200 and AP6. By establishing an AP connection between terminal 200 and AP6, terminal 200 can participate as a slave station in the wireless network formed by AP6 and communicate with the printer 10 via AP6.

[0080] (Bootstrapping (BS) and Authentication (Auth) in Case A; Figure 8) Referring to Figure 8, the BS processing and Auth processing in Case A will be explained. T455 is the same as T25 in Figure 2 (i.e., Figure 3), except that terminal 200 photographs the AP QR code on printer 10.

[0081] In T500, terminal 200 generates its public key TPK3 and private key tsk3. T502 is the same as T202 in Figure 4, except that it generates a shared key SK3 using terminal 200's private key tsk3 and printer 10's public key PPK1. T504 is the same as T204 in Figure 4, except that it encrypts a random value RV2 using the shared key SK3 to generate encrypted data ED2.

[0082] In this case, for example, the user has performed an operation on terminal 200 to select to receive CO from another device. Therefore, T510 sends an AReq to printer 10 that includes a value indicating that terminal 200 can operate only as an Enrollee in terms of its capability. Furthermore, this AReq includes the public key TPK3 of terminal 200 generated by T500, the encrypted data ED3 generated by T504, and the MAC address "mac_ap".

[0083] When printer 10 receives an AReq from terminal 200 at T510, T511a determines that the received AReq contains the MAC address "mac_ap" (YES at S4 in Figure 7). At T511b, printer 10 determines that the first printer CO is stored in memory 34 as AP information 44 (YES at S10). At T511c, printer 10 determines that the received AReq contains a value indicating that terminal 200 can operate only as an Enrollee in terms of capability (YES at S12). Then, at T511d, printer 10 determines its capability to be "Configurator" (S14).

[0084] Next, printer 10 performs authentication similar to that shown in T212-T218 in Figure 4, and the authentication is successful (S30). Specifically, at T512, printer 10 generates a shared key SK3 using the public key TPK3 of terminal 200 in AReq and the private key psk1 of printer 10. At T514, printer 10 decrypts the encrypted data ED3 in AReq using the shared key SK3 and obtains a random value RV3. Then, at T516, printer 10 generates a new public key PPK3 and a new private key psk3. At T517, printer 10 generates a shared key SK3 using the public key TPK3 of terminal 200 in AReq and the private key psk3 of printer 10. At T518, printer 10 encrypts the random value RV3 and a new random value RV4 using the shared key SK3 to generate encrypted data ED4.

[0085] Next, printer 10 sends ARes to terminal 200 at T520, which includes printer 10's public key PPK3, encrypted data ED4, and printer 10's capability (i.e., a value indicating that it can operate only as a Configurator) (S32).

[0086] When terminal 200 receives ARes from printer 10 at T520, it performs authentication similar to T222 and T224 in Figure 4, and the authentication is successful. That is, at T522, terminal 200 generates a shared key SK4 using terminal 200's private key tsk3 generated at T500 and printer 10's public key PPK3 in ARes, and at T524, it decrypts the encrypted data ED4 in ARes using the shared key SK4 and obtains random values ​​RV3 and RV4.

[0087] In T530, terminal 200 sends a Confirm to printer 10. The Confirm includes information indicating that terminal 200 will act as the Enrollee and printer 10 will act as the Configurator. As a result, in T532, terminal 200 decides to act as the Enrollee, and in T534, printer 10 decides to act as the Configurator.

[0088] (Configuration (Config) and Network Access (NA) in Case A; Figure 9) Refer to Figure 9 to explain the processing of Config and NA in Case A. That is, Figure 9 is a continuation of Figure 8. In this case, terminal 200 is the Enrollee. Therefore, in T600, terminal 200 sends CReq to printer 10. In this case, CReq contains the value "sta" but does not contain the value "config".

[0089] When printer 10 receives a CReq from terminal 200 at T600, at T602, it obtains the hash value HV1, the group ID "Group1", and the public key TPK2 from the first printer CO, which is AP information 44. Next, at T604, printer 10 generates the first terminal CO. Specifically, printer 10 performs the following processes.

[0090] Printer 10 generates a specific value by hashing the combination of the hash value HV1, the group ID "Group1", and the public key TPK3 of terminal 200 in the AReq of T510 in Figure 8. Then, according to ECDSA, printer 10 generates an electronic signature DSta1 by encrypting the generated specific value using the secret key tsk2 contained in the operation information received from terminal 100 at T310 in Figure 5. As a result, printer 10 can generate a first terminal SC containing the hash value HV1, the group ID "Group1", the public key TPK3 of terminal 200, and the electronic signature DSta1. Then, printer 10 generates a first terminal CO containing the first terminal SC and the public key TPK2.

[0091] In T610, printer 10 sends a CRes containing the first terminal CO to terminal 200. As a result, terminal 200 receives the first terminal CO, and T612 stores the first terminal CO.

[0092] Next, terminal 200 transmits a DReq including the first terminal SC to AP6 via T620.

[0093] When AP6 receives a DReq from terminal 200 at T620, it performs DReq authentication at T622, similar to T402 in Figure 6. In the case of Figure 9, the hash value HV1 and group ID "Group1" in the received first terminal SC match the hash value HV1 and group ID "Group1" in the stored AP CO in the AP SC, respectively. Therefore, AP6 determines that authentication is successful in the first AP determination process.

[0094] AP6 then uses the stored public key TPK2 contained in the AP CO to decrypt the digital signature DSta1 in the received first terminal SC. In the case shown in Figure 9, the decryption of the digital signature DSta1 is successful. In this case, AP6 determines that the authentication is successful in the second AP decision process because the specific value obtained by decrypting the digital signature DSpr1 matches the value obtained by hashing each piece of information in the received first terminal SC (i.e., the hash value HV1, "Group1", and the public key TPK3).

[0095] Next, in T624, AP6 generates a connection key CK2 according to ECDH, using the acquired public key TPK3 of terminal 200 and the stored private key ask2 of AP6. In T630, AP6 sends a DRes containing the SC for AP to terminal 200.

[0096] When terminal 200 receives DRes from AP6 at T630, it performs DRes authentication at T632, similar to T412 in Figure 6. Terminal 200 first performs a first TA determination process similar to the first PR determination process. In the case of Figure 9, the hash value HV1 and group ID "Group1" in the received AP SC match the hash value HV1 and group ID "Group1" in the first terminal SC contained in the stored first terminal CO, respectively. Therefore, terminal 200 determines that authentication is successful in the first TA determination process.

[0097] Next, terminal 200 performs a second TA decision process similar to the second PR decision process. Specifically, terminal 200 uses the public key TPK2 contained in the stored first terminal CO to decrypt the digital signature DSap1 in the received AP SC. In this case, terminal 200 determines that authentication is successful in the second TA decision process because the specific value obtained by decrypting the digital signature DSap1 matches the value obtained by hashing each piece of information in the received AP SC (i.e., hash value HV1, "Group1", and public key APK2).

[0098] Next, in T634, terminal 200 generates a connection key CK2 in accordance with ECDH, using the stored private key tsk3 of terminal 200 and the acquired public key APK2 of AP6. As a result, terminal 200 and AP6 establish an AP connection in T640 using the connection key CK2.

[0099] (Specific Case B; Figures 10 and 11) Referring to Figures 10 and 11, we will now explain a specific case B realized by the process in Figure 7. Case B, like Case A, is a continuation of the process in Figure 2 (i.e., Figures 3 to 6). That is, in the initial state of Case A, an AP connection is established between printer 10 and AP6. Also, terminal 200 has established an AP connection with AP8. In this case, each device 8, 10, and 200 performs communication according to the DPP method, thereby establishing a new AP connection between printer 10 and AP8. This allows printer 10 to be reconnected from AP6 to AP8.

[0100] (Bootstrapping (BS) and Authentication (Auth) in Case B; Figure 10) Refer to Figure 10 to explain the BS processing and Auth processing in Case B. T655 is the same as T455 in Figure 8. T700~T704 are the same as T500~T504 in Figure 8.

[0101] In this case, the user has not performed any operation to select terminal 200 to receive CO from another device. Therefore, in T710, terminal 200 sends an AReq to printer 10 that includes a value indicating that terminal 200 can operate as either a Configurator or an Enrollee as part of its capability. T710 is the same as T510 in Figure 8, except that the capability value of terminal 200 is different.

[0102] T711a and T711b are the same as T511a and T511b in Figure 8. In T511c, printer 10 determines that the received AReq does not contain a value that indicates that terminal 200 can operate only as Enrollee in terms of capability (NO in S12). Then, in T711d, printer 10 determines that printer 10's capability is "Enrollee" (S16).

[0103] T712 to T718 are the same as T512 to T518 in Figure 8. T720 is the same as T520 in Figure 8, except that ARes includes a value indicating that printer 10 can operate as Enrollee only as a capability.

[0104] T722 and T724 are the same as T522 and T524 in Figure 8. T730 is the same as T530 in Figure 8, except that Confirm includes information indicating that terminal 200 will act as a Configurator and printer 10 will act as an Enrollee. As a result, in T732, terminal 200 decides to act as a Configurator, and in T534, printer 10 decides to act as an Enrollee.

[0105] (Configuration (Config) and Network Access (NA) in Case B; Figure 11) Refer to Figure 11 to explain the Config and NA processing in Case B. That is, Figure 11 is a continuation of Figure 10. In this case, printer 10 is the Enrollee. Therefore, in T800, printer 10 sends CReq to terminal 200. In this case, CReq contains the values ​​"sta" and "config".

[0106] When terminal 200 receives a CReq from printer 10 at T800, T802 retrieves the group ID "Group2", public key TPK10, and private key tsk10 from terminal 200's memory (not shown). In this case, an AP connection has been established between terminal 200 and AP8. That is, terminal 200 has already performed a Config according to the DPP method with AP8, and at this time, it generates the group ID "Group2", public key TPK10, and private key tsk10 and stores them in memory. That is, at T802, terminal 200 retrieves each piece of information stored in the Config. Next, at T804, terminal 200 generates the first printer CO. Specifically, terminal 200 generates the hash value HV2 by hashing terminal 200's public key TPK10. Furthermore, terminal 200 generates a specific value by hashing the combination of the hash value HV2, the group ID "Group2", and the public key PPK3 of printer 10 in the ARes of T720 in Figure 10. Then, terminal 100 generates the digital signature DSpr2 by encrypting the generated specific value using terminal 200's private key tsk10. As a result, terminal 100 generates a first printer SC containing the hash value HV2, the group ID "Group2", the public key PPK3 of printer 10, and the digital signature DSpr2. Then, terminal 100 generates a first printer CO containing the first printer SC and terminal 200's public key TPK10.

[0107] In T810, terminal 200 sends a CRes containing the first printer CO to printer 10. As a result, printer 10 stores the first printer CO received in T810 as AP information 44 in T812, replacing the first printer CO stored as AP information 44 (i.e., the first printer CO used for AP connection with AP6). In other words, AP information 44 is updated.

[0108] As described above, in this case, an AP connection is established between terminal 200 and AP8. Therefore, AP8 stores AP8's public key APK10 and private key ask10, and also stores the AP CO received from terminal 200. The AP CO includes the AP SC and terminal 100's public key TPK10. The AP SC also includes the hash value HV2, the group ID "Group2", AP8's public key APK10, and the digital signature DSap2. The digital signature DSap2 is information encrypted by terminal 200's private key tsk10, which is obtained by hashing the combination of the hash value HV2, the group ID "Group2", and the public key APK10, and is a different value from the digital signature DSpr2 included in the first printer CO.

[0109] Steps T820 to T834 are similar to steps T400 to T414 in Figure 6, except that communication takes place mainly between AP8 and printer 10, and that connection key CK3 is generated using the public key PPK3 and private key ask10 (or private key psk3 and public key APK10). As a result, printer 10 and AP8 establish an AP connection in step T840 using connection key CK3.

[0110] (Specific case C; Figures 12-15) Referring to Figures 12 to 15, we will explain the specific case C realized by the process in Figure 7. Case C, like Case A, is a continuation of the process in Figure 2 (i.e., Figures 3 to 6). That is, in the initial state of Case C, an AP connection is established between printer 10 and AP6. In this case, a WFD connection is established between printer 10 and terminal 200 when the user selects the "WFD communication" button.

[0111] (Bootstrapping (BS) in Case C; Figure 12) Referring to Figure 12, the processing of BS in Case C will be explained. T850 and T852 are the same as T100 and T102 in Figure 3. In T854, the user operates the operation unit 12 to select the "WFD communication" button on the selection screen. T856 is the same as T106 in Figure 3, except that the WFD QR code is displayed on the display unit 14. The WFD QR code is obtained by encoding the public key PPK1 of the printer 10 and the MAC address "mac_wfd" used for WFD connection.

[0112] T870 and T872 are the same as T120 and T122 in Figure 3, except that the QR code for WFD is scanned by terminal 200 and the MAC address "mac_wfd" is obtained by terminal 200.

[0113] Next, terminal 200 and printer 10 perform WFD Discovery communication in T880 according to the WFD method. WFD Discovery is communication for searching for printer 10.

[0114] Next, at T890, terminal 200 and printer 10 perform G / O Negotiation communication according to the WFD method. G / O Negotiation is communication to determine whether to operate in the G / O state or the CL state. In this case, it is decided that printer 10 will be in the G / O state and terminal 200 will be in the CL state. As a result, at T892, terminal 200 will be in the CL state, and at T894, printer 10 will be in the G / O state. For example, whether printer 10 or terminal 200 will be in the G / O state is determined by various factors such as the specifications of printer 10 or terminal 200. In this embodiment, if an AP connection is established between printer 10 and any AP, printer 10 will be in the G / O state, and if an AP connection is not established between printer 10 and any AP, printer 10 will be in the CL state. In a modified example, it may be decided that terminal 200 will be in the G / O state and printer 10 will be in the CL state.

[0115] (Authentication (Auth) in Case C; Figure 13) Refer to Figure 13 to explain the authentication process in Case C. That is, Figure 13 is a continuation of Figure 12. T900~T904 are the same as T500~T504 in Figure 8. T910 is the same as T510 in Figure 8, except that AReq includes a value indicating that terminal 200 can operate as either a Configurator or an Enrollee, and the MAC address "mac_wfd".

[0116] When printer 10 receives an AReq from terminal 200 at T910, it determines at T911a that the received AReq contains the MAC address "mac_wfd" (NO at S4 in Figure 7). At T911c, since printer 10 is in the G / O state (YES at S20), printer 10's capability is determined to be "Configurator" (S24). Steps T912 to T934 are the same as steps T512 to T534 in Figure 8.

[0117] (Configuration in Case C; Figure 14) Refer to Figure 14 to explain the Config process in Case C. That is, Figure 14 is a continuation of Figure 13. T1000 is the same as T600 in Figure 9.

[0118] In T1002, printer 10 generates its public key PPK4 and private key psk4. Then, in T1004, printer 10 generates a second terminal CO. Specifically, printer 10 performs the following processes.

[0119] First, printer 10 generates a hash value HV3 by hashing its public key PPK4. Then, printer 10 generates a specific value by hashing a combination of the hash value HV3, the group ID "Group3", and the public key TPK3 of terminal 200 in the AReq of T910 in Figure 13. Next, printer 10 generates a digital signature DSta3 by encrypting the generated specific value using the private key psk4 according to ECDSA. As a result, printer 10 can generate a second terminal SC containing the hash value HV3, the group ID "Group3", the public key TPK3 of terminal 200, and the digital signature DSta3. Finally, printer 10 generates a second terminal CO containing the second terminal SC and the public key PPK4.

[0120] At T1010, printer 10 sends a CRes containing the second terminal CO to terminal 200. As a result, terminal 200 receives the second terminal CO and stores it at T1012.

[0121] (Network Access (NA) in Case C; Figure 15) Refer to Figure 15 to explain the handling of NA in Case C. That is, Figure 15 is a continuation of Figure 14.

[0122] In T1020, printer 10 generates its public key PPK5 and private key psk5. Then, in T1022, printer 10 generates a second printer CO. Specifically, printer 10 performs the following processes.

[0123] Printer 10 generates a specific value by hashing the combination of the hash value HV3, the group ID "Group3", and the public key PPK5 generated by T1020. Then, according to ECDSA, Printer 10 generates a digital signature DSpr3 by encrypting the generated specific value using the private key psk4. As a result, Printer 10 can generate a second printer SC containing the hash value HV3, the group ID "Group3", Printer 10's public key PPK5, and the digital signature DSpr3. Then, Printer 10 generates a second terminal CO containing the second printer SC and the public key PPK4.

[0124] In T1030, printer 10 sends a DReq containing a second printer SC to terminal 200.

[0125] When terminal 200 receives a DReq from printer 10 at T1030, it performs DReq authentication at T1032, similar to T402 in Figure 6. Specifically, terminal 200 determines that the hash value HV3 and group ID "Group3" in the received second printer SC match the stored hash value HV3 and group ID "Group3" in the second terminal SC, respectively. Then, terminal 200 decrypts the digital signature DSpr3 in the received second printer SC using the stored public key PPK4 in the second terminal CO. Terminal 200 determines that the specific value obtained by decrypting the digital signature DSpr3 matches the value obtained by hashing each piece of information in the received second printer SC (i.e., the hash value HV3, "Group3", and public key PPK5). Based on the above, terminal 200 determines that the DReq authentication was successful.

[0126] Next, at T1034, terminal 200 generates a connection key CK4 according to ECDH, using the stored private key tsk3 of terminal 200 and the acquired public key PPK5 of printer 10. At T1040, terminal 200 sends a DRes containing a second terminal SC to printer 10.

[0127] When printer 10 receives DRes from terminal 200 at T1040, it performs DRes authentication at T1042, similar to T412 in Figure 6. Specifically, printer 10 determines that the hash value HV3 and group ID "Group3" in the received second terminal SC match the stored hash value HV3 and group ID "Group3" in the second printer SC, respectively. Then, printer 10 decrypts the digital signature DSta3 in the received second terminal SC using the stored public key PPK4 in the second printer CO. printer 10 determines that the specific value obtained by decrypting the digital signature DSta3 matches the value obtained by hashing each piece of information in the received second terminal SC (i.e., hash value HV3, "Group3", and public key TPK3). Based on the above, printer 10 determines that DRes authentication was successful.

[0128] Next, at T1044, the printer 10 generates a connection key CK4 in accordance with ECDH, using the acquired public key TPK3 of the terminal 200 and the stored private key psk5 of the printer 10. As a result, the printer 10 and the terminal 200 establish a WFD connection at T1050 using the connection key CK4.

[0129] (Table summarizing each case in this embodiment; Figure 16) Referring to Figure 16, we will explain each case realized by the authentication process of printer 10 in Figure 7. As shown in each case from row 1 to 8 in Figure 16, the capability of printer 10 is determined.

[0130] Cases 1-4 in line numbers indicate that an AP connection has been established between the terminal that scanned the QR code on printer 10 (i.e., the "Initiator terminal") and one of the APs (e.g., AP6) during BS processing.

[0131] In the case of line number 1, an AP connection has not been established between the printer 10 and any AP (e.g., AP6), and the "AP Communication" button is selected on the selection screen displayed on the printer 10 (see T102 in Figure 3). This case corresponds to the cases in Figures 2 to 6. That is, in a situation where an AP connection has been established between the Initiator terminal and AP6, the printer 10 establishes an AP connection with AP6. In this case, the printer 10 determines that AReq contains the MAC address "mac_ap" (YES in S4 in Figure 7) and determines that AP information 44 is not stored in memory 34 (NO in S10). As a result, the printer 10 determines its capability to be "Enrollee" (S16). In this case, the printer 10 receives a CO from the Initiator terminal and can join the wireless network that the Initiator terminal is currently participating in as a slave station.

[0132] The case in line number 2 represents a situation where no AP connection is established between printer 10 and any AP, and the "WFD communication" button is selected on the selection screen. This case corresponds to the case where a WFD connection is established between printer 10 and the Initiator terminal. In this case, printer 10 determines that AReq contains the MAC address "mac_wfd" (NO in S4 of Figure 7). Since no AP connection is established between printer 10 and any AP, printer 10 enters the CL state (NO in S20). As a result, printer 10 determines its capability to be "Enrollee" (S26). In this case, printer 10 can communicate with the Initiator terminal according to the WFD method, depending on whether the "WFD communication" button is selected.

[0133] The case in line number 3 shows a situation where an AP connection is established between printer 10 and AP6, and the "AP Communication" button is selected on the selection screen. This case corresponds to case B in Figures 10 and 11. That is, it corresponds to a situation where an AP connection is established between the Initiator terminal and AP8, and printer 10 is reconnected from AP6 to AP8. In this case, printer 10 determines its capability to be "Enrollee" (T711a to T711d in Figure 10, S16 in Figure 7).

[0134] The case in line number 4 shows a scenario where an AP connection is established between printer 10 and one of the APs, and the "WFD communication" button is selected on the selection screen. This case corresponds to a scenario where an AP connection is established between the Initiator terminal and one of the APs, but a WFD connection is established between printer 10 and the Initiator terminal. In this case, printer 10 determines that AReq contains the MAC address "mac_wfd" (NO in S4 of Figure 7). Since an AP connection is established between printer 10 and one of the APs, printer 10 enters the G / O state (YES in S20). As a result, printer 10 determines its capability to be "Configurator" (S24). In this case, although printer 10 can perform communication via the AP, for security reasons, it can perform communication with the Initiator terminal according to the WFD method.

[0135] Furthermore, cases 5 through 8 indicate situations where an AP connection has not been established between the Initiator terminal and any of the APs (e.g., AP6).

[0136] Case 5 is the same as case 1, except that no AP connection has been established between the Initiator terminal and any AP. In this case, when no AP connection has been established between the Initiator terminal and AP6, the printer 10 establishes an AP connection with AP6. For example, after an AP connection has been established between the printer 10 and AP6, the Initiator terminal can scan the QR code attached to AP6, thereby establishing an AP connection between the Initiator terminal and AP6 as well. In this case, the printer 10 determines its capability to be "Enrollee" (S16 in Figure 7). In this case, both the printer 10 and the Initiator terminal can participate in the wireless network formed by the APs.

[0137] The case in line 6 is the same as the case in line 2, except that no AP connection has been established between the Initiator terminal and any AP. In this case, the printer 10 determines its capability to be "Enrollee" (S26 in Figure 7). In this case, even though neither the printer 10 nor the Initiator terminal has established a Wi-Fi connection with an AP, the printer 10 can communicate with the Initiator terminal according to the WFD method.

[0138] Case 7 is the same as case 3, except that no AP connection has been established between the Initiator terminal and any AP. This case corresponds to case A in Figures 8 and 9. That is, in a situation where no AP connection has been established between the Initiator terminal and any AP, and an AP connection has been established between printer 10 and AP6, the Initiator terminal establishes an AP connection with AP6. In this case, printer 10 determines its capability to "Configurator" (T511a to T511d in Figure 8, S14 in Figure 7). In this case, printer 10 sends a CO to the Initiator terminal, allowing the Initiator terminal to join the wireless network that printer 10 is currently participating in as a slave station.

[0139] Case 8 is the same as case 4, except that no AP connection is established between the Initiator terminal and any AP. This case corresponds to case C in Figures 12 to 15. That is, although an AP connection is established between the printer 10 and any AP, the printer 10 establishes a WFD connection with the Initiator terminal. In this case, the printer 10 determines its capability to be "Configurator" (T911a, T911c in Figure 13, S24 in Figure 7). In this case, although the printer 10 can communicate via the AP, for security reasons it can communicate with the Initiator terminal according to the WFD method.

[0140] (Effects of this embodiment) In this embodiment, the printer 10 determines whether or not AP information 44 is stored in memory 34, that is, whether or not an AP connection has been established between the printer 10 and any access point (S10 in Figure 7). If an AP connection has been established between the printer 10 and AP6 (YES in S10), the printer 10 takes on the role of Configurator (S14) and sends a first terminal CO to terminal 200 (T610 in Figure 9, case of line number 7 in Figure 16). As a result, an AP connection can be established between terminal 200 and AP6 (T640). If an AP connection has not been established between the printer 10 and any access point (NO in S10), the printer 10 takes on the role of Enrollee (S16) and receives a first printer CO from terminal 100 (T310 in Figure 5, case of line number 1 in Figure 16). As a result, an AP connection can be established between the printer 10 and AP6. Therefore, the printer 10 can take on an appropriate role, taking into account its own circumstances.

[0141] Furthermore, when an AP connection is established between the printer 10 and any access point, the printer 10 determines whether AReq contains a value indicating that the Initiator terminal can operate only as an Enrollee (S12 in Figure 7). If the printer 10 determines that AReq contains the value (YES in S12 in Figure 7), it assumes the role of Configurator (S14, case of line 7 in Figure 16). On the other hand, if the printer 10 determines that AReq does not contain the value (NO in S12 in Figure 7), it assumes the role of Enrollee (S16, case of line 3 in Figure 16). With this configuration, the printer 10 can assume the appropriate role by considering both the status of the printer 10 itself and the status of the Initiator terminal.

[0142] (Correspondence) Printer 10, display unit 14, and Wi-Fi I / F 16 are examples of the "first communication device," "display unit," and "wireless interface," respectively. The AP QR code and WFD QR code are examples of "output information." The Initiator terminal (e.g., terminal 100) is an example of the "second communication device." AReq (i.e., DPP Authentication Request) is an example of an "authentication request." ARes (i.e., DPP Authentication Response) is an example of a "first authentication response (and second authentication response)." capability "Configurator" and capability "Enrollee" are examples of "first role information" and "second role information," respectively. The first terminal CO of T610 in Figure 9 is an example of "first wireless configuration information." The first printer CO of T310 in Figure 5 is an example of "second wireless configuration information." AP6 is an example of the "first access point." In the case of line 1 in Figure 16, AP6 is an example of the "second access point." In the case of line 3 in Figure 16, AP8 is an example of a "second access point". In the AReq of T510 in Figure 8, the value indicating that terminal 200 can operate as an Enrollee only is an example of "predetermined information". MAC addresses "mac_ap" and "mac_wfd" are examples of "first usage information" and "second usage information", respectively. AP information 44 is an example of "access point information".

[0143] T106 in Figure 3 is an example of processing implemented by the "Output Control Unit". S2, S10, S32, and S42 in Figure 7 are examples of processing implemented by the "Authentication Request Receiving Unit", "First Determination Unit", "First Authentication Response Transmission Unit", and "Second Authentication Response Transmission Unit", respectively. T310 in Figure 5 and T420 in Figure 6 are examples of processing implemented by the "First Wireless Setting Receiving Unit" and "First Establishment Unit", respectively. T610 in Figure 9 is an example of processing implemented by the "Wireless Setting Transmission Unit".

[0144] The specific examples of the technology disclosed herein have been described in detail above, but these are merely illustrative and do not limit the scope of the claims. The technology described in the claims includes various modifications and changes to the specific examples described above. The following are some examples of modifications.

[0145] (Modification 1) In Figure 3, at T106, the printer 10 may, instead of displaying the QR code, have the print execution unit 18 print the QR code. In this modification, the process of having the print execution unit 18 print the QR code is an example of "output control processing".

[0146] (Modification 2) The printer 10 and the terminal 100 may each be further equipped with a wireless interface (e.g., BTI / F, NFCI / F, etc.) that conforms to a wireless method other than the Wi-Fi method (e.g., BT (abbreviation for Bluetooth®), NFC (abbreviation for Near Field Communication), etc.). In this case, at T106 in Figure 3, the printer 10 may instruct the BTI / F of the printer 10 to transmit DPP information including, for example, the public key PPK1 and the MAC address "mac_ap". In this case, the terminal 100 can receive the DPP information via the BTI / F of the terminal 100. In this modification, instructing the BTI / F to transmit DPP information is an example of "output control processing". In another modification, at T106 in Figure 3, the printer 10 may store the DPP information in the NFCI / F of the printer 10. In this case, the terminal 100 can receive the DPP information via the NFCI / F of the terminal 100. In this modified example, storing DPP information in NFCI / F is one example of "output control processing".

[0147] (Modification 3) In the above case A, the printer 10 performs the process shown in Figure 2 according to the DPP method to establish an AP connection with AP6. Then, at T610 in Figure 9, the printer 10 generates a first terminal SC using the first printer CO stored in the process shown in Figure 2, and transmits the first terminal CO to terminal 200. Alternatively, the printer 10 may establish an AP connection with AP6 by performing communication using a wireless profile (i.e., SSID (Service Set Identifier) ​​and password) according to another Wi-Fi method different from the DPP method (for example, the WPS (Wi-Fi Protected Setup) method). In this case, in the Config process, the printer 10 may transmit to terminal 200 a first terminal CO containing the wireless profile stored in the printer 10 according to the other method, instead of the first terminal SC. As a result, terminal 200 can establish an AP connection with AP6 using the received wireless profile. In this modification, the wireless profile is an example of "first wireless configuration information". In this modified example, the printer 10 may determine in S4 of Figure 7 whether or not a wireless profile is stored as AP information 44. In this modified example, the wireless profile is an example of "access point information".

[0148] (Modification 4) In the above case B, terminal 200 establishes an AP connection with AP8 by performing communication according to the DPP method. Then, terminal 200 generates a first printer SC using the information stored in the communication according to the DPP method at T810 in Figure 11, and sends a first printer CO to printer 10. Alternatively, terminal 200 may establish an AP connection with AP8 by performing communication according to another Wi-Fi method different from the DPP method (for example, the WPS (Wi-Fi Protected Setup) method). In this case, printer 10 may receive a first printer CO from terminal 200 that includes a wireless profile stored in terminal 200 using the other method, instead of the first printer SC. In this modification, the wireless profile is an example of "second wireless configuration information".

[0149] (Modification 5) The Wi-Fi I / F 116 may support the SoftAP method developed by the Wi-Fi Alliance instead of the WFD method. In this case, the selection screen of T102 in Figure 3 may include a "SoftAP communication" button instead of a "WFD communication" button. Here, the AP QR code displayed when the "AP communication" button on the selection screen is selected is obtained by encoding the public key PPK1 and first information indicating that communication via the AP will be used. On the other hand, the SoftAP QR code displayed when the "SoftAP communication" button on the selection screen is selected is obtained by encoding the public key PPK1 and second information indicating that communication according to the SoftAP method without going through the AP will be used. Furthermore, in this modification, the printer 10 may, in the authentication process, determine whether or not AReq contains the first information instead of making the decision in S4 in Figure 7. If the printer 10 determines that AReq contains the first information, it may proceed to S10 and establish an AP connection with the AP (e.g., AP6). Furthermore, if AReq determines that the printer 10 contains the second information, the printer 10 may decide its capability to be either "Configurator" or "Enrollee" and establish a Wi-Fi connection with the Initiator terminal in accordance with the SoftAP method. In this modified example, the first information and the second information are examples of "first usage information" and "second usage information," respectively.

[0150] (Modification 6) The process in S12 of Figure 7 does not need to be executed. In this modification, in the case of row number 3 of the table in Figure 16, the printer 10 may determine its capability to be "Configurator". Then, in a situation where an AP connection is established between the Initiator terminal and AP8, the printer 10 may generate a first terminal CO for AP6 and send the first terminal CO to the Initiator terminal. The Initiator terminal may then reconnect from AP8 to AP6. In this modification, the "second determination unit" and "predetermined information" can be omitted.

[0151] (Modification 7) The processes S4, S20-S26 in Figure 7 do not need to be executed. That is, a WFD connection does not need to be established between the printer 10 and the Initiator terminal. In this modification, the "second establishment unit," "first usage information," "second usage information," and "third wireless connection" can be omitted.

[0152] (Modification 8) In the above embodiment, the printer 10 determines whether or not AP information 44 is stored in memory 34 (S10 in Figure 7). Alternatively, the printer 10 may, for example, attempt to send an acknowledgment signal to the AP and determine whether or not a response signal to the acknowledgment signal is received. If the printer 10 determines that a response signal is received, it may proceed to S12, and if it determines that a response signal is not received, it may proceed to S16. In this modification, "access point information" can be omitted.

[0153] (Modification 9) The "first communication device" does not have to be the printer 10, but may be other devices such as a scanner, multifunction device, mobile terminal, PC, or server. Also, the "second communication device" does not have to be the terminal 100, but may be other devices such as a printer, scanner, multifunction device, or camera.

[0154] (Modification 10) In the above embodiment, each process in Figures 2 to 15 is implemented by software (e.g., program 40), but at least one of these processes may be implemented by hardware such as a logic circuit.

[0155] The technical elements described herein or in the drawings demonstrate technical usefulness individually or in various combinations, and are not limited to the combinations described in the claims at the time of filing. Furthermore, the technologies illustrated herein or in the drawings can achieve multiple objectives simultaneously, and achieving even one of these objectives constitutes technical usefulness in itself. The following are the features of the technology disclosed herein. (Item 1) A first communication device, A wireless interface for performing wireless communication in accordance with the Wi-Fi standard, Output control unit that performs output control processing to output output information in accordance with the Wi-Fi standard, which is obtained using the public key of the first communication device, to the outside; An authentication request receiving unit receives an authentication request using the public key from a second communication device that has acquired the public key, via the wireless interface. A first determination unit that determines whether or not a wireless connection has been established between the first communication device and any access point, A first authentication response transmitting unit transmits to the second communication device via the wireless interface a first authentication response to the second communication device, which includes first role information indicating that the first communication device assumes a first role, when the authentication request is received from the second communication device and it is determined that a wireless connection has been established between the first communication device and the first access point, wherein the first role is to transmit to the second communication device first wireless configuration information for the second communication device to establish a first wireless connection with the first access point, A wireless setting transmission unit transmits the first wireless setting information to the second communication device via the wireless interface after the first authentication response has been transmitted to the second communication device. A second authentication response transmitting unit transmits to the second communication device via the wireless interface a second authentication response to the second communication device, which includes second role information indicating that the first communication device assumes a second role different from the first role, when the authentication request is received from the second communication device and it is determined that a wireless connection has not been established between the first communication device and any access point, wherein the second role is to receive second wireless configuration information from the second communication device for the first communication device to establish a second wireless connection with the second access point, After the second authentication response is transmitted to the second communication device, the first wireless setting receiving unit receives the second wireless setting information from the second communication device via the wireless interface, A first establishment unit that uses the second wireless configuration information to establish the second wireless connection with the second access point via the wireless interface, A first communication device equipped with the following: (Item 2) The first communication device as described in item 1, wherein the first determination unit determines whether or not a wireless connection has been established between the first communication device and any access point when the authentication request is received from the second communication device. (Item 3) The first communication device further includes, The second determination unit determines whether or not the authentication request includes predetermined information when the authentication request is received from the second communication device, wherein the predetermined information is information indicating that the second communication device performs the second role. The first authentication response transmission unit, when it determines that a wireless connection has been established between the first communication device and the first access point, and when it determines that the authentication request includes the predetermined information, transmits the first authentication response including the first role information to the second communication device via the wireless interface. The first communication device according to item 1 or 2, wherein the second authentication response transmission unit further determines that a wireless connection has been established between the first communication device and the first access point, and determines that the authentication request does not include the predetermined information, transmits the second authentication response including the second role information to the second communication device via the wireless interface. (Item 4) The aforementioned authentication request includes either first usage information relating to the use of communication via an access point, or second usage information relating to the use of communication not via an access point. The first determination unit determines whether a wireless connection has been established between the first communication device and any access point when the authentication request includes the first usage information. The first communication device further includes, The first communication device according to any one of items 1 to 3, further comprising a second establishment unit that establishes a third wireless connection between the second communication device and an access point via the wireless interface when the authentication request includes the second usage information. (Item 5) The third wireless connection is a wireless connection in accordance with the Wi-Fi Direct method of the Wi-Fi standard, as described in item 4, for the first communication device. (Item 6) The first communication device assumes the first role when the first communication device is in the Group Owner state in the Wi-Fi Direct method, The first communication device is the first communication device described in item 5, which performs the second role when the first communication device is in the Client state in the Wi-Fi Direct method. (Item 7) The output information is information in accordance with the Device Provisioning Protocol method of the Wi-Fi standard, the first communication device as described in any one of items 1 to 6. (Item 8) The first communication device, as described in any one of items 1 to 7, determines that a wireless connection has been established between the first communication device and any access point when access point information relating to an access point with which a wireless connection has been established is stored in memory. (Item 9) The access point information is the first communication device described in item 8, which includes a Signed Connector in accordance with the Device Provisioning Protocol of the Wi-Fi standard. (Item 10) The output information is a code image obtained by encoding the public key. The output control process is a process for displaying the output information, which is the code image, on a display unit, according to the first communication device described in any one of items 1 to 9. (Item 11) A computer program for a first communication device, The first communication device is, It is equipped with a wireless interface for performing wireless communication in accordance with the Wi-Fi standard, The computer of the first communication device is comprised of the following parts, namely: Output control unit that performs output control processing to output output information in accordance with the Wi-Fi standard, which is obtained using the public key of the first communication device, to the outside; An authentication request receiving unit receives an authentication request using the public key from a second communication device that has acquired the public key, via the wireless interface. A first determination unit that determines whether or not a wireless connection has been established between the first communication device and any access point, A first authentication response transmitting unit transmits to the second communication device via the wireless interface a first authentication response to the second communication device, which includes first role information indicating that the first communication device assumes a first role, when the authentication request is received from the second communication device and it is determined that a wireless connection has been established between the first communication device and the first access point, wherein the first role is to transmit to the second communication device first wireless configuration information for the second communication device to establish a first wireless connection with the first access point, A wireless setting transmission unit transmits the first wireless setting information to the second communication device via the wireless interface after the first authentication response has been transmitted to the second communication device. A second authentication response transmitting unit transmits to the second communication device via the wireless interface a second authentication response to the second communication device, which includes second role information indicating that the first communication device assumes a second role different from the first role, when the authentication request is received from the second communication device and it is determined that a wireless connection has not been established between the first communication device and any access point, wherein the second role is to receive second wireless configuration information from the second communication device for the first communication device to establish a second wireless connection with the second access point, After the second authentication response is transmitted to the second communication device, the first wireless setting receiving unit receives the second wireless setting information from the second communication device via the wireless interface, A first establishment unit that uses the second wireless configuration information to establish the second wireless connection with the second access point via the wireless interface, A computer program that functions as such. [Explanation of symbols]

[0156] 2: Communication system, 6, 8: AP, 10: Printer, 12: Operation unit, 14: Display unit, 16: Wi-Fi I / F, 18: Print execution unit, 30: Control unit, 32: CPU, 34: Memory, 40: Program, 44: AP information, 100: Terminal, 115: Camera, 116: Wi-Fi I / F, 200: Terminal, 215: Camera, 216: Wi-Fi I / F, PPK1, PPK2, PPK3, PPK4, PPK5: Public key (printer), TPK1, TPK2, TPK3, TPK10: Public key (terminal), APK1, APK2, APK10: Public key (AP), psk1, psk2, psk3, psk4, psk5: Private key (printer), tsk1, tsk2, tsk3, tsk10: Private key (terminal), ask1, ask2, ask10: Private key (AP), RV1, RV2, RV3, RV4: Random value, ED1, ED2, ED3, ED4: Encrypted data, SK1, SK2, SK3, SK4: Shared key, HV1, HV2, HV3: Hash value, DSpr1, DSpr2, DSpr3: Digital signature (printer), DSta1, DSta3: Digital signature (terminal), DSap1, DSap2: Digital signature (AP), CK1, CK2, CK3, CK4: Connection key

Claims

1. A first communication device, A wireless interface for performing wireless communication in accordance with the Wi-Fi standard, Output control unit that performs output control processing to output output information in accordance with the Wi-Fi standard, obtained using the public key of the first communication device, to the outside; An authentication request receiving unit receives an authentication request using the public key from a second communication device that has acquired the public key, via the wireless interface. A first authentication response transmission unit transmits to the second communication device via the wireless interface a first authentication response containing first role information indicating that the first communication device assumes a first role, when the authentication request is received from the second communication device and the authentication request includes a first MAC address used by the first communication device for communication via an access point, wherein the first role is to transmit to the second communication device first wireless configuration information for the second communication device to establish a first wireless connection with the first access point, A wireless setting transmission unit transmits the first wireless setting information to the second communication device via the wireless interface after the first authentication response has been transmitted to the second communication device. A second authentication response transmitting unit transmits to the second communication device via the wireless interface a second authentication response containing second role information indicating that the first communication device assumes a second role different from the first role, when the authentication request is received from the second communication device and the authentication request includes a second MAC address used by the first communication device for communication that does not go through an access point, wherein the second role is to receive second wireless configuration information from the second communication device for the first communication device to establish a second wireless connection with the second access point, After the second authentication response is transmitted to the second communication device, the first wireless setting receiving unit receives the second wireless setting information from the second communication device via the wireless interface, A first establishment unit establishes a second wireless connection with the second access point via the wireless interface using the second wireless configuration information, A first communication device comprising the following:

2. The first authentication response transmission unit transmits the first authentication response, including the first role information, to the second communication device via the wireless interface when it receives the authentication request from the second communication device, the first MAC address is included in the authentication request, and a wireless connection is established between the first communication device and any access point. The first communication device according to claim 1, wherein the second authentication response transmission unit further transmits the second authentication response, including the second role information, to the second communication device when the authentication request is received from the second communication device, the first MAC address is included in the authentication request, and the first communication device has not established a wireless connection with the access point.

3. The first communication device according to claim 2, further comprising a determination unit that determines whether or not a wireless connection has been established between the first communication device and any access point when the authentication request is received from the second communication device.

4. The determination unit determines that a wireless connection has been established between the first communication device and any access point when access point information relating to an access point with which a wireless connection has been established is stored in memory, according to claim 3 of the first communication device.

5. The first communication device according to claim 4, wherein the access point information includes a Signed Connector in accordance with the Device Provisioning Protocol of the Wi-Fi standard.

6. The first authentication response transmission unit receives the authentication request from the second communication device, the first MAC address is included in the authentication request, and the authentication request includes predetermined information indicating that the second communication device assumes the second role, and transmits the first authentication response including the first role information to the second communication device via the wireless interface. The first communication device according to any one of claims 1 to 5, wherein the second authentication response transmission unit further transmits the second authentication response, including the second role information, to the second communication device via the wireless interface when the authentication request is received from the second communication device, the first MAC address is included in the authentication request, and the authentication request does not include the predetermined information.

7. The second authentication response transmission unit receives the authentication request from the second communication device, the second MAC address is included in the authentication request, and the first communication device is not in Group Owner state, and transmits the second authentication response including the second role information to the second communication device via the wireless interface. The first authentication response transmission unit further transmits the first authentication response, including the first role information, to the second communication device via the wireless interface when it receives the authentication request from the second communication device, the second MAC address is included in the authentication request, and the first communication device is in the Group Owner state. The first communication device further includes: A first communication device according to any one of claims 1 to 6, comprising: a second establishment unit for establishing a WFD connection with the second communication device operating as a Group Owner via the wireless interface when the second MAC address is included in the authentication request and the first communication device is not in the Group Owner state; and a second establishment unit for establishing a WFD connection with the second communication device operating as a Client via the wireless interface when the second MAC address is included in the authentication request and the first communication device is in the Group Owner state.

8. The first communication device according to any one of claims 1 to 7, wherein the output information is information in accordance with the Device Provisioning Protocol of the Wi-Fi standard.

9. The output information is a code image obtained by encoding the public key. The first communication device according to any one of claims 1 to 8, wherein the output control process is a process for displaying the output information, which is the code image, on a display unit.

10. A computer program for a first communication device, The first communication device is It is equipped with a wireless interface for performing wireless communication in accordance with the Wi-Fi standard, The computer of the first communication device is comprised of the following parts, namely: Output control unit that performs output control processing to output output information in accordance with the Wi-Fi standard, obtained using the public key of the first communication device, to the outside; An authentication request receiving unit receives an authentication request using the public key from a second communication device that has acquired the public key, via the wireless interface. A first authentication response transmission unit transmits to the second communication device via the wireless interface a first authentication response containing first role information indicating that the first communication device assumes a first role, when the authentication request is received from the second communication device and the authentication request includes a first MAC address used by the first communication device for communication via an access point, wherein the first role is to transmit to the second communication device first wireless configuration information for the second communication device to establish a first wireless connection with the first access point, A wireless setting transmission unit transmits the first wireless setting information to the second communication device via the wireless interface after the first authentication response has been transmitted to the second communication device. A second authentication response transmitting unit transmits to the second communication device via the wireless interface a second authentication response containing second role information indicating that the first communication device assumes a second role different from the first role, when the authentication request is received from the second communication device and the authentication request includes a second MAC address used by the first communication device for communication that does not go through an access point, wherein the second role is to receive second wireless configuration information from the second communication device for the first communication device to establish a second wireless connection with the second access point, After the second authentication response is transmitted to the second communication device, the first wireless setting receiving unit receives the second wireless setting information from the second communication device via the wireless interface, A first establishment unit establishes a second wireless connection with the second access point via the wireless interface using the second wireless configuration information, A computer program that functions as such.

Citation Information

Patent Citations

  • Communication device, communication method, and program

    JP2018037978A

  • Communication device, control of the same, and program

    JP2018046435A

  • Communication device, control method of the same, and program

    JP2019029989A

  • Communication device

    JP2019103107A

  • Device provisioning protocol (DPP) using assisted bootstrapping

    US20180109418A1