Application programs for terminal devices, terminal devices, and communication devices
The described configuration for wireless connections between devices uses the OSI reference model and DPP method to securely establish and manage connections, addressing security and convenience issues in wireless communication.
Patent Information
- Authority / Receiving Office
- JP · JP
- Patent Type
- Patents
- Current Assignee / Owner
- BROTHER KOGYO KK
- Filing Date
- 2022-03-18
- Publication Date
- 2026-06-02
AI Technical Summary
Existing methods for establishing wireless connections between communication devices and access points lack security and convenience, particularly in scenarios where devices need to transition between different connection protocols.
A terminal device and communication device configuration that utilizes the OSI reference model for secure communication of bootstrapping keys, combined with the DPP method for authentication, allowing secure and efficient establishment of wireless connections by prioritizing DPP when supported, and fallback to traditional methods when necessary.
Ensures secure and user-friendly wireless connections by enabling secure communication of bootstrapping keys and reducing the need for manual password entry, enhancing user convenience and security.
Smart Images

Figure 0007868359000001 
Figure 0007868359000002 
Figure 0007868359000003
Abstract
Description
Technical Field
[0001] This specification discloses a technique for establishing a wireless connection between a communication device and an access point.
Background Art
[0002] Patent Document 1 discloses a technique for establishing a Wi-Fi connection between a printer and an access point (hereinafter referred to as "AP") using a terminal according to the DPP (abbreviation for Device Provisioning Protocol) method. In this technique, the terminal obtains the respective public keys of the printer and the AP by reading a QR code (registered trademark) in which information including the public key is encoded, and uses these public keys to establish a Wi-Fi connection between the printer and the AP.
Prior Art Documents
Patent Documents
[0003]
Patent Document 1
Summary of the Invention
Problems to be Solved by the Invention
[0004] This specification provides a technique for securely establishing a wireless connection between a communication device and an access point.
Means for Solving the Problems
[0005] This specification discloses an application program for a terminal device. The terminal device comprises a wireless interface for performing wireless communication in accordance with the Wi-Fi standard, a memory for storing access point information, wherein the access point information is information for establishing a first wireless connection with a target access point, and a computer. The application program controls the computer, namely, a first establishment unit for establishing a second wireless connection with a communication device via the wireless interface, wherein the second wireless connection is a connection for which the communication device operates as a master station and the terminal device operates as a slave station, and when the second wireless connection is established with the communication device, the application program uses the second wireless connection to communicate via the wireless interface using OSI (Open Systems Initiative). The device may function as follows: a key communication execution unit that executes communication of the bootstrapping key of the terminal device or the communication device with the communication device by performing communication at or above the network layer of the reference model (abbreviation for Interconnection); a second establishment unit that, if the second wireless connection is disconnected after the bootstrapping key communication has been performed with the communication device, uses the access point information in the memory to establish the first wireless connection with the target access point via the wireless interface; an authentication request communication unit that, when the first wireless connection is established with the target access point, executes communication of the authentication request in accordance with the Wi-Fi standard's DPP (abbreviation for Device Provisioning Protocol) method, in which the bootstrapping key is used, with the communication device via the wireless interface; and a first connection information transmission unit that, when the authentication request communication is performed with the communication device, transmits first connection information in accordance with the DPP method to the communication device via the wireless interface, wherein the first connection information is information for establishing a wireless connection between the communication device and the target access point.
[0006] According to the above configuration, the terminal device communicates the bootstrapping key of the terminal device or communication device with the communication device by performing communication at or above the network layer of the OSI reference model. In this way, since the terminal device performs communication at or above the network layer, the bootstrapping key can be communicated securely. For this reason, a secure wireless connection can be established between the communication device and the target access point.
[0007] This specification also discloses a communication device. The communication device includes a first wireless interface for performing wireless communication in accordance with the Wi-Fi standard, a second wireless interface for performing wireless communication in accordance with the Wi-Fi standard, a first Probe request transmission unit that repeatedly transmits a first Probe request via the first wireless interface when a first predetermined operation is received from a user, and a first establishment unit that establishes a first wireless connection with the first access point via the first wireless interface when a first Probe response containing information indicating an automatic wireless connection is received from a first access point via the first wireless interface in response to the transmission of the first Probe request, and The Probe Response Transmission Unit transmits a second Probe response to the terminal device via the second wireless interface when a second Probe request is received from the terminal device via the second wireless interface; the Second Establishment Unit establishes a second wireless connection with the terminal device via the second wireless interface when the second Probe response is transmitted to the terminal device, wherein the second wireless connection is a connection for the communication device to operate as a master station and the terminal device to operate as a slave station; the Key Communication Execution Unit, when the second wireless connection is established with the terminal device, uses the second wireless connection to perform communication at or above the network layer of the OSI (Open Systems Interconnection) reference model via the second wireless interface to perform communication of the bootstrapping key of the terminal device or the communication device with the terminal device; and after the bootstrapping key communication has been performed with the terminal device, the Key Communication Execution Unit transmits the Wi-Fi standard DPP (Device Provisioning) via the first wireless interface.The system may include: an authentication request communication unit that performs communication of the authentication request, in accordance with the Protocol (abbreviation for Protocol), using the bootstrapping key, with the terminal device; a connection information receiving unit that receives connection information in accordance with the DPP method from the terminal device via the first wireless interface when the communication of the authentication request is performed with the terminal device; and a third establishment unit that, when the connection information is received from the terminal device, uses the connection information to establish a third wireless connection with the second access point via the first wireless interface.
[0008] According to the above configuration, the communication device performs communication at or above the network layer of the OSI reference model, thereby communicating the bootstrapping key of the terminal device or the communication device with the terminal device. In this way, because the communication device performs communication at or above the network layer, the bootstrapping key can be transmitted securely. For this reason, a secure wireless connection can be established between the communication device and the second access point.
[0009] The computer-readable recording medium for storing the application program for the above-mentioned terminal device, the terminal device itself, and the method executed by the terminal device are also novel and useful. The computer program for realizing the above-mentioned communication device, the computer-readable storage medium for storing the computer program, and the method executed by the above-mentioned communication device are also novel and useful. Furthermore, a communication system comprising the above-mentioned terminal device and the above-mentioned communication device is also novel and useful. [Brief explanation of the drawing]
[0010] [Figure 1] This shows the configuration of the communication system. [Figure 2] This shows a flowchart of the application processing performed by the application program on the device. [Figure 3] This shows a flowchart of the connection process performed by the printer. [Figure 4] The sequence diagram for Case A is shown. [Figure 5] The sequence diagram for Case B is shown. [Figure 6] The sequence diagram for Case B-1 is shown. [Figure 7] The sequence diagram for Case B-2 is shown. [Figure 8] The sequence diagram for Case B-3 is shown. [Figure 9] The sequence diagram for Case C is shown below. [Modes for carrying out the invention]
[0011] (Examples) (Configuration of communication system 2; Figure 1) As shown in Figure 1, the communication system 2 comprises a terminal 10, multiple printers 100, 200, and multiple APs (Access Points) 6A, 6B. The technology of this embodiment is a technology that uses the terminal 10 to establish a wireless connection (hereinafter referred to as "Wi-Fi connection") between a printer (e.g., 100) and an AP (e.g., 6A) in accordance with the Wi-Fi standard.
[0012] (Configuration of terminal 10) Terminal 10 is a portable terminal device such as a mobile phone (e.g., a smartphone), PDA, or tablet PC. In a modified example, terminal 10 may be a stationary PC, notebook PC, etc. Terminal 10 comprises an operation unit 12, a display unit 14, a Wi-Fi interface 16, and a control unit 30. Each unit 12 to 30 is connected to a bus line (symbol omitted). Hereafter, the interface will be referred to as "I / F".
[0013] The control unit 12 is equipped with multiple keys. By operating the control unit 12, the user can input various instructions to the terminal 10. The display unit 14 is a display for showing various information. The display unit 14 also functions as a so-called touch panel (i.e., a control unit that accepts user input).
[0014] Wi-FiI / F16 is a wireless interface for performing Wi-Fi communication in accordance with the Wi-Fi standard. The Wi-Fi standard is a wireless communication standard for performing wireless communication in accordance with the IEEE (The Institute of Electrical and Electronics Engineers, Inc.) 802.11 standard and equivalent standards (e.g., 802.11a, 11b, 11g, 11n, 11ac, etc.). In particular, Wi-FiI / F16 supports the DPP (Device Provisioning Protocol) method developed by the Wi-Fi Alliance. Details of the DPP method are described in the "Wi-Fi Easy Connect (trademark) Specification Version 2.0" standard document created by the Wi-Fi Alliance. Furthermore, Wi-FiI / F16 also supports the WFD (Wi-Fi Direct (trademark)) method developed by the Wi-Fi Alliance. Details of the WFD method are described in the "Wi-Fi Direct (trademark) Specification Version 1.9" standard document created by the Wi-Fi Alliance.
[0015] The Wi-Fi I / F16 is physically a single chip. However, the Wi-Fi I / F16 is assigned two MAC addresses, which enables the creation of a first I / F16A assigned to the first MAC address and a second I / F16B assigned to the second MAC address. In the modified version, the first I / F16A and the second I / F16B may be composed of different chips.
[0016] The first I / F 16A is an I / F for performing wireless communication according to a method different from the WFD method (e.g., a normal Wi-Fi method, DPP method, etc.). The normal Wi-Fi method is a method for establishing a Wi-Fi connection with an AP by using an SSID (abbreviation for Service Set Identifier) for identifying the AP and a password authenticated by the AP. The second I / F 16B is an I / F for performing wireless communication according to the WFD method. In this embodiment, since there is no situation where the terminal 10 performs wireless communication according to the WFD method, there is no description of the use of the second I / F 16B hereafter.
[0017] The control unit 30 includes a CPU 32 and a memory 34. The CPU 32 executes various processes according to programs 36, 38 stored in the memory 34. The memory 34 is composed of a volatile memory, a non-volatile memory, etc.
[0018] The OS (abbreviation for Operating System) program 36 is a program for realizing the basic operations of the terminal 10. In this embodiment, the OS program 36 assumes Android (registered trademark). However, in a modified example, the OS program 36 may be another OS program. Hereinafter, the OS program will be referred to as "OS". The application 38 is a program for, for example, establishing a Wi-Fi connection between the terminal 10 and an AP (e.g., AP6A), or establishing a Wi-Fi connection between a printer (e.g., 100) and an AP (e.g., AP6A). Hereinafter, the application will be referred to as "app".
[0019] Application 38 is installed on terminal 10 from a server on the Internet (not shown) provided, for example, by the vendor of OS 36 or the vendor of printers 100, 200. By supplying instructions to OS 36, application 38 can cause OS 36 to execute various processes, or cause other applications to execute various processes via OS 36. Therefore, each process executed by OS 36 or other applications in response to instructions from application 38 can be said to be a process realized by application 38 (i.e., the CPU 32 functions as the execution unit that executes the said process).
[0020] Memory 34 further stores AP information for terminal 10 to establish a Wi-Fi connection with an AP. The AP information includes the AP's SSID and password. The AP information may be information about the AP with which terminal 10 currently has a Wi-Fi connection, or it may be information about APs with which terminal 10 has previously established a Wi-Fi connection.
[0021] (Configuration of printers 100 and 200) The printer 100 is a peripheral device (for example, a peripheral device of terminal 10) capable of performing printing functions. In a modified example, the printer 100 may be a multifunction device capable of performing scanning functions, fax functions, etc., in addition to printing functions. The printer 100 has a printer ID "AAA". The printer 100 comprises an operation unit 112, a display unit 114, a Wi-Fi interface 116, a print execution unit 118, and a control unit 130. Each unit 112 to 130 is connected to a bus line (symbol omitted).
[0022] The control unit 112 includes multiple buttons, including a Wi-Fi button 113. The user can input various instructions to the printer 100 by operating the control unit 112. The display unit 114 is a display for showing various information. The display unit 114 also functions as a so-called touch panel (i.e., a control unit that accepts user input). The print execution unit 118 includes a printing mechanism such as an inkjet or laser printer.
[0023] The Wi-Fi I / F116 is a wireless interface for performing Wi-Fi communication in accordance with the Wi-Fi standard. In particular, the Wi-Fi I / F116 supports the DPP and SoftAP methods. The Wi-Fi I / F116 is physically a single chip. However, the Wi-Fi I / F116 is assigned two MAC addresses, MA and MB, which enables the implementation of a first I / F116A assigned to MAC address MA and a second I / F116B assigned to MAC address MB. In modified versions, the first I / F116A and the second I / F116B may be composed of different chips.
[0024] The first interface, I / F116A, is an interface for performing wireless communication according to the standard Wi-Fi and DPP methods. The second interface, I / F116B, is an interface for performing wireless communication according to the DPP and SoftAP methods. The SoftAP method is a method in which the printer 100 acts as the base station (i.e., SoftAP) of the Wi-Fi network to establish a Wi-Fi connection with other devices (e.g., terminal 10).
[0025] The Wi-Fi I / F116 also supports WPS (Wi-Fi Protected Setup), a standard developed by the Wi-Fi Alliance. WPS is a technology known as automatic wireless connection or easy wireless connection, which allows for easy Wi-Fi connection between two devices without the user having to manually enter connection information (such as SSID and password). In particular, the Wi-Fi I / F116 supports the WPS PBC (Push Button Configuration) method. The PBC method is a method for establishing a Wi-Fi connection between two devices when a predetermined operation is performed on each of the devices by the user.
[0026] The control unit 130 comprises a CPU 132 and a memory 134. The CPU 132 performs various processes according to a program 136 stored in the memory 134. The memory 134 is composed of volatile memory, non-volatile memory, etc.
[0027] Printer 200 is a peripheral device capable of performing printing functions (for example, a peripheral device of terminal 10) and has a printer ID "BBB". Printer 200 has the same configuration as printer 100, except that its Wi-Fi interface (not shown) does not support the DPP method.
[0028] (AP6A, 6B configuration) The AP6A is a standard access point, also known as a wireless access point or wireless LAN router. The AP6A supports the DPP method. The AP6A relays communication between a pair of devices belonging to a Wi-Fi network where the AP6A acts as the master station. The AP6A stores the SSID "S1" and PW "P1". SSID "S1" is information identifying the Wi-Fi network formed by the AP6A. PW "P1" is authentication information used when allowing other devices to join the Wi-Fi network. The AP6A supports the WPS PBC method and is equipped with a WPS button 61.
[0029] The AP6B stores the SSID "S2" and PW "P2" and is equipped with a WPS button 62. The AP6B has the same configuration as the AP6A.
[0030] (App processing; Figure 2) Referring to Figure 2, the application processing performed by the CPU 32 of terminal 10 according to application 38 will be described. The application processing in Figure 2 is triggered when a setup operation is performed by the user.
[0031] When the user operates the setup button included in the screen displayed by the application 38, the CPU 32 determines that the setup operation has been accepted and proceeds to S10. In S10, the CPU 32 obtains AP information from memory 34. In this embodiment, the AP information is information about the AP on which terminal 10 has currently established a Wi-Fi connection via the first I / F 16A. Hereinafter, the AP will be referred to as the "target AP," and the SSID that identifies the target AP (i.e., the SSID included in the AP information) will be referred to as the "target SSID."
[0032] In S12, the CPU 32 sends a disconnection signal to the target AP via the first I / F 16A, thereby disconnecting the Wi-Fi connection with the target AP. This allows the CPU 32 to establish a Wi-Fi connection with another device (a printer in this embodiment) via the first I / F 16A.
[0033] In S14, CPU32 establishes a Wi-Fi connection with the printer via the first I / F16A. This printer is a printer that functions as a SoftAP (i.e., a master station) in response to a Wi-Fi button press from the user. Hereafter, this printer will be referred to as the "target printer".
[0034] In S16, CPU32 uses the Wi-Fi connection established in S14 to perform communication at the network layer or higher of the OSI (Open System Interconnection) reference model via the first I / F16A. Specifically, CPU32 sends a query request to inquire about device information related to the target printer. This device information includes information indicating whether the target printer supports the DPP method, the printer ID of the target printer, the capabilities information of the target printer, and one or more SSIDs that identify one or more APs on which the target printer can establish a Wi-Fi connection. The capabilities information indicates the printing capabilities that the target printer can perform (e.g., number of colors, resolution, whether or not double-sided printing is possible).
[0035] In S20, CPU32 uses the Wi-Fi connection established in S14 to monitor for a response from the target printer via the first I / F16A. If CPU32 receives a response from the target printer (YES in S20), it proceeds to S22. If it does not receive a response from the target printer (NO in S20), it returns to S16 and sends the request again to the target printer.
[0036] In S22, the CPU 32 uses the information contained in the received query response to display a connection selection screen on the display unit 14. The connection selection screen allows the user to select the SSID of the AP (Access Point) that should establish a Wi-Fi connection with the target printer. The connection selection screen includes the printer ID, capability information, and one or more SSIDs contained in the query response. By viewing the connection selection screen, the user can confirm the device information related to the target printer.
[0037] If the query response contains two or more SSIDs, the CPU 32 further determines whether those two or more SSIDs include the target SSID in the AP information obtained in S10. If the CPU 32 determines that those two or more SSIDs include the target SSID, it displays a connection selection screen on the display unit 14 in which the target SSID is positioned at the top and the other SSIDs are positioned at the bottom. In other words, on the connection selection screen, the target SSID is displayed with priority over other SSIDs. This allows the user to appropriately select the target SSID (i.e., the SSID of the AP with which terminal 10 has currently established a Wi-Fi connection).
[0038] In S24, CPU32 accepts the user's selection of one SSID from the connection selection screen. Hereafter, the SSID selected here will be referred to as the "selected SSID," and the AP identified by the selected SSID will be referred to as the "selected AP."
[0039] In S30, CPU32 determines whether the selected SSID and the target SSID match. If CPU32 determines that the selected SSID and the target SSID match (YES in S30), it proceeds to S32; otherwise, it proceeds to S50.
[0040] In S32, CPU32 determines whether the target printer supports the DPP method. Specifically, if the query response received in S20 contains information indicating that the target printer supports the DPP method, CPU32 determines that the target printer supports the DPP method (YES in S32) and proceeds to S34. If the query response does not contain such information, CPU32 determines that the target printer does not support the DPP method (NO in S32) and proceeds to S50.
[0041] In S34, CPU32 uses the Wi-Fi connection established in S14 to send a DPP execution request to the target printer via the first I / F16A. The DPP execution request is a request to change the state of the target printer from DPPOFF to DPPON. The DPPOFF state is when the target printer is unable to send an Authentication Response to an Authentication Request according to the DPP method, and the DPPON state is when the target printer is able to send an Authentication Response. Hereafter, Authentication will be referred to as "Auth", Request as "Req", and Response as "Res".
[0042] As described above, terminal 10 transitions the target printer's state from DPPOFF to DPPON by sending a DPP execution request to the target printer. The DPPON state is usually a state where the processing load on the target printer is higher compared to the DPPOFF state. Since the target printer's state is maintained in the DPPOFF state during the period before Auth is executed (i.e., until S32), the processing load on the target printer can be reduced. Then, as the target printer's state transitions to the DPPON state at the time Auth is about to be executed, the target printer can appropriately send an Auth Res to terminal 10 in response to receiving an Auth Req from terminal 10.
[0043] In S35, CPU32 uses the Wi-Fi connection established in S14 to perform communication at the network layer or higher of the OSI reference model via the first I / F16A. Specifically, CPU32 receives Bootstrapping information (hereinafter referred to as "BS information") from the target printer. The BS information includes the target printer's public key.
[0044] In S36, the CPU 32 uses the Wi-Fi connection established in S14 to send a disconnection request to the target printer via the first I / F 16A. This disconnects the Wi-Fi connection established in S14. As a result, the CPU 32 can establish a Wi-Fi connection with another device (the target AP in this embodiment) via the first I / F 16A.
[0045] In S38, CPU32 uses the AP information obtained in S10 via the first I / F16A to re-establish a Wi-Fi connection with the target AP.
[0046] In S40, CPU32 executes DPP communication processing. DPP communication processing is the process of establishing a Wi-Fi connection between the target printer and the target AP by performing various communications such as authentication according to the DPP method with the target printer. When S40 is completed, the process shown in Figure 2 is completed.
[0047] In S50, the CPU 32 displays an input screen on the display unit 14. The input screen is a screen that prompts the user to enter the password for the selected AP, which is identified by the selected SSID.
[0048] In S52, CPU32 obtains the password by accepting password input from the user.
[0049] In S60, the CPU32 uses the Wi-Fi connection established in S14 to send a connection command to the target printer via the first I / F16A. The connection command is a signal instructing the target printer to establish a Wi-Fi connection with the AP using the SSID and password included in the command. This establishes a Wi-Fi connection between the target printer and the selected AP. When S60 ends, the process shown in Figure 2 is completed.
[0050] As described above, if terminal 10 is YES in S30, it sends a DPP execution request to the target printer (S34), receives BS information from the target printer (S35), and executes DPP communication processing using the BS information. On the other hand, if terminal 10 is NO in S30, it prompts the user to enter the password for the selected AP without receiving BS information from the target printer (S50). In other words, in cases where DPP communication processing is executed, the user does not need to enter the password for the selected AP. By prioritizing the execution of the DPP method when terminal 10 is YES in S30, terminal 10 can omit the user from entering a password. This improves user convenience. In a modified example, if terminal 10 is NO in S32, it may omit S50 and S52 and send a connection instruction including the AP information obtained in S10 to the target printer in S60.
[0051] Furthermore, in S60, without DPP authentication, a connection instruction containing information for the target printer to establish a Wi-Fi connection with the selected AP (i.e., the SSID and password of the selected AP) is sent to the target printer. As a result, there is a possibility that the SSID and password of the selected AP may be leaked. In contrast, in S40, after DPP authentication is performed, information for the target printer to establish a Wi-Fi connection with the selected AP is sent to the target printer. As a result, the communication of this information is performed securely. Terminal 10 can securely communicate information for the target printer to establish a Wi-Fi connection with the selected AP by prioritizing the DPP process when S30 is YES.
[0052] (Printer processing; Figure 3) Next, referring to Figure 3, the connection process executed by the CPU 132 of the printer 100 according to program 136 will be described. The connection process in Figure 3 is triggered when the user operates the Wi-Fi button 113 (hereinafter referred to as "Wi-Fi button operation").
[0053] When the user presses the Wi-Fi button, the CPU 132 proceeds to S80. In the modified version, the CPU 132 may also proceed to S80 when the printer 100 is powered on, even if the printer 100 has not yet stored the information necessary to establish a Wi-Fi connection with the AP.
[0054] In S80, CPU 132 activates SoftAP (Software Access Point). This causes printer 100 to operate as the base station of the Wi-Fi network. Thus, printer 100 transitions to base station mode in response to Wi-Fi button input from the user, allowing the user to transition to base station mode at their desired time. Communication according to the SoftAP method is performed via the second I / F 116B.
[0055] In S82, the CPU 132 sends a Probe request by broadcast via the first I / F 116A. As a result, the CPU 132 receives Probe responses, including the SSID of each AP, from each of the one or more APs present around the printer 100 via the first I / F 116A.
[0056] In S84, the CPU 132 determines whether or not there is a Probe response among the one or more Probe responses received that contains information indicating that WPS is in progress. If the CPU 132 determines that there is a Probe response containing information indicating that WPS is in progress (YES in S84), it proceeds to S120. If it determines that there is no such Probe response (NO in S84), it proceeds to S90.
[0057] In S120, CPU32 executes the WPS connection process. The WPS connection process is the process of establishing a Wi-Fi connection with the source AP that sent the Probe response containing information indicating that WPS is in progress, according to the WPS method. When S120 is completed, the process shown in Figure 3 is completed.
[0058] In S90, CPU132 monitors for a Probe request from a terminal (e.g., 10) via the second I / F116B. If CPU132 receives a Probe request from the terminal (YES in S90), it proceeds to S92; otherwise, it returns to S84.
[0059] In S92, CPU 132 establishes a Wi-Fi connection with the terminal that sent the Probe request in S90. Hereafter, this terminal will be referred to as the "target terminal". Printer 100 establishes a Wi-Fi connection with the target terminal and adds the target terminal as a slave station to the wireless network in which Printer 100 operates as the master station.
[0060] In S100, the CPU 132 performs query response processing. This query response processing is the process of sending device information of the printer 100 to the target terminal. Specifically, the CPU 132 first sends a Probe request by broadcast via the first I / F 116A and receives Probe responses containing the SSID of each of the one or more APs present around the printer 100. Each of the one or more APs that sent the one or more Probe responses can be said to be an AP on which the printer 100 can establish a Wi-Fi connection. Subsequently, using the Wi-Fi connection established in S92, the CPU 132 receives a query request from the target terminal via the second I / F 116B and sends a query response containing device information to the target terminal. The device information includes one or more SSIDs included in the one or more Probe responses received from the one or more APs mentioned above. In this way, the printer 100 sends the SSIDs of one or more access points (APs) that it can establish a Wi-Fi connection with to the target terminal, so that it can properly establish a Wi-Fi connection with one or more of those APs.
[0061] In S102, the CPU 132 determines whether or not it has received a DPP execution request from the target terminal. If the CPU 132 receives a DPP execution request (see S34 in Figure 2) from the target terminal via the second I / F 116B, it determines YES in S102 and proceeds to S110. If the CPU 132 receives a connection instruction (see S60 in Figure 2) from the target terminal via the second I / F 116B, it determines NO in S102 and proceeds to S130.
[0062] In S110, CPU 132 executes the DPP connection process. The DPP connection process is the process of establishing a Wi-Fi connection with the target AP according to the DPP method. When S110 is completed, the process shown in Figure 3 is completed.
[0063] In S130, CPU 132 executes a non-DPP connection process. The non-DPP connection process uses the SSID and password of the selected AP included in the connection instruction to establish a Wi-Fi connection with the selected AP (i.e., an AP different from the target AP) according to the normal Wi-Fi method, which is different from the DPP method. When S130 is completed, the process shown in Figure 3 is completed.
[0064] (Specific cases; Figures 4-9) Referring to Figures 4 to 9, we will explain specific cases realized by the processing in Figures 2 and 3. For ease of understanding, the operations performed by the CPUs 32 and 132 of each device will be described from the perspective of each device (e.g., terminal 10, printer 100) rather than from the perspective of the CPU. In Figures 4 to 9, regarding communication between printer 100 and each device 10, 6A, and 6B, communication performed via the first I / F 116A of printer 100 is shown with a solid line, and communication performed via the second I / F 116B is shown with a dashed line. Since all communication performed by terminal 10 is performed via the first I / F 16A, the phrase "via the first I / F 16A" will be omitted when describing communication performed by terminal 10.
[0065] (Case A; Figure 4) Referring to Figure 4, Case A, in which a Wi-Fi connection is established between printer 100 and AP6A according to the WPS method, will be explained. In the initial state shown in Figure 4, terminal 10 has established a Wi-Fi connection with AP6A. Therefore, terminal 10 has stored AP6A's AP information (i.e., SSID "S1", PW "P1"). Note that printer 100 has not yet stored AP information, for example, when it is first powered on after being shipped.
[0066] At T2, printer 100 receives a power-on operation from the user. Next, at T4, printer 100 receives a Wi-Fi button operation from the user (trigger for the process in Figure 3). In this case, at T6, printer 100 starts SoftAP (S80). The SoftAP of printer 100 uses SSID "S3" and PW "P3". Next, at T8, printer 100 broadcasts a Probe request via the first I / F 116A (S82).
[0067] At T10, AP6A starts operating according to the WPS method by accepting an operation of the WPS button 61 from the user. Specifically, at T8, when AP6A receives a Probe request from printer 100, at T12 it sends a Probe response to printer 100 that includes the SSID "S1" and information indicating that WPS is in progress.
[0068] At T12, printer 100 receives a Probe response from AP6A via the first I / F 116A, which includes information indicating that WPS is being executed (YES at S84). In this case, at T14, printer 100 establishes a Wi-Fi connection with AP6A according to the WPS method (S120). Thus, in case A, the user can establish a Wi-Fi connection between printer 100 and AP6A according to the WPS method PBC method by pressing the WPS button 61 on AP6A without entering the password for AP6A.
[0069] (Case B; Figure 5) Next, referring to Figure 5, we will explain Case B, in which a Wi-Fi connection is established between the printer 100 and the terminal 10. The initial state in Figure 5 is the same as the initial state in Figure 4, and the processing of T102 to T108 is the same as T2 to T8 in Figure 4.
[0070] In this case, AP6A does not accept a WPS button operation from the user (see T10 in Figure 4). In this case, at T112, AP6A sends a Probe response to printer 100 that includes AP6A's SSID "S1" but does not include information indicating that WPS is in progress.
[0071] At T112, printer 100 receives a Probe response from AP6A via the first I / F116A that does not contain information indicating that WPS is running (NO at S84).
[0072] When terminal 10 receives an application launch command from the user at T120, it launches application 38 at T122. Furthermore, terminal 10 receives a setup command for application 38 from the user at T124 (trigger for the process in Figure 2). In this case, terminal 10 obtains AP information for AP6A (i.e., SSID "S1", PW "P1") from memory 34 at T130 (S10).
[0073] Next, terminal 10 sends a disconnection signal to AP6A via the first I / F16A at T132 (S12). This disconnects the Wi-Fi connection between terminal 10 and AP6A. Furthermore, terminal 10 broadcasts a Probe request at T140.
[0074] At T140, printer 100 receives a Probe request from terminal 10 via the second I / F116B (YES at S90). In this case, at T142, printer 100 sends a Probe response containing the SSID "S3" to terminal 10 via the second I / F116B.
[0075] The application 38 on terminal 10 has pre-stored the SSID "S3" and password "P3" of the printer 100, which operates as a SoftAP. Therefore, when terminal 10 receives a Probe response from printer 100 at T142, it determines that the SSID "S3" included in the Probe response matches the stored SSID "S3". In other words, terminal 10 determines that the printer 100, the source of the Probe response, is the target for connection. Then, at T144, terminal 10 establishes a Wi-Fi connection with printer 100 using the stored password "P3" (S14).
[0076] At T144, when printer 100 establishes a Wi-Fi connection with terminal 10 via the second I / F 116B (S92), the process proceeds to Figure 6. Hereafter, this Wi-Fi connection will be referred to as a "temporary connection".
[0077] (Case B-1; Figure 6) Next, referring to Figure 6, we will explain Case B-1, in which a Wi-Fi connection following the DPP method is established between printer 100 and AP6A using a temporary connection.
[0078] At T150, printer 100 broadcasts a Probe request via the first I / F 116A (S100). As a result, at T152, printer 100 receives a Probe response from AP6A via the first I / F 116A including the SSID "S1" (S100), and at T154, receives a Probe response from AP6B via the first I / F 116A including the SSID "S2" (S100).
[0079] Terminal 10, using a temporary connection at T160, sends an inquiry request to printer 100 (S16).
[0080] When printer 100 receives an inquiry request from terminal 10 via the second I / F 116B using a temporary connection at T160, it sends an inquiry response to terminal 10 via the second I / F 116B using the temporary connection at T162 (S100). The inquiry response includes device information for printer 100. In this case, the device information includes DPP support information indicating that printer 100 supports the DPP method, the printer ID "AAA" of printer 100, the capabilities information of printer 100, and the two SSIDs "S1" and "S2" received at T152 and T154. In a modified example, printer 100 may execute the processes at T150 to T154 after receiving the inquiry request from terminal 10 at T160.
[0081] When terminal 10 receives a query response from printer 100 using a temporary connection in T162 (YES in S20), it displays the connection selection screen SC1 in T170 using the information contained in the query response (S22). The connection selection screen SC1 includes the printer ID "AAA", the capabilities information of printer 100, and two SSIDs "S1" and "S2". Here, SSID "S1", which is included in the AP information stored in terminal 10, is displayed above (i.e., preferentially) the other SSID "S2".
[0082] Terminal 10 accepts the user's selection of SSID "S1" at T172 (S24). Terminal 10 determines that the selected SSID "S1" matches the SSID included in the AP information obtained at T130 (i.e., the AP information in terminal 10's memory 34) (YES at S30), and determines that the received inquiry response at S162 contains DPP support information (YES at S32). In this case, at T180, terminal 10 uses a temporary connection to send a DPP execution request to printer 100 (S34).
[0083] When printer 100 receives a DPP execution request from terminal 10 via the second I / F 116B using a temporary connection at T80 (YES at S102), it transitions from the DPPOFF state to the DPPON state at T181 (S110). In this case, at T182, printer 100 generates its public key PKpr using the MAC address MA of printer 100's first I / F 116A (S110). Specifically, the public key PKpr includes a string indicating the MAC address MA. In this way, since the public key PKpr is generated from the MAC address MA, which is unique identification information assigned to printer 100, it is possible to suppress the duplication of public keys among various printers, including printer 100. Also, since printer 100 generates the public key PKpr at T182, it does not need to store the public key PKpr in advance.
[0084] Next, at T184, the printer 100 uses a temporary connection to transmit BS information, including the public key PKpr, MAC address MA, and channel information CI, to the terminal 10 via the second I / F 116B (S110). The channel information CI is information indicating one or more channels (in other words, frequency bandwidths) available to the printer 100.
[0085] Terminal 10 receives BS information using a temporary connection in T184 (S35). The processing in T184 corresponds to bootstrapping in the DPP method. Next, terminal 10 sends a disconnection request to printer 100 using the temporary connection in T186 (S36).
[0086] When printer 100 receives a disconnection request from terminal 10 via the second I / F 116B using a temporary connection at T186, it stops SoftAP at T190. This disconnects the temporary connection between printer 100 and terminal 10.
[0087] Terminal 10 establishes a Wi-Fi connection with AP6A at T192 using the AP information (i.e., SSID "S1", PW "P1") obtained at T130 in Figure 5 (S38).
[0088] Once a Wi-Fi connection is established between terminal 10 and AP6A, terminal 10 sends an Auth Request to printer 100 using the public key PKpr included in the BS information, with the MAC address MA included in the BS information as the destination (S40). Here, terminal 10 repeatedly sends the Auth Request to printer 100 by sequentially using one or more channels indicated by the channel information CI included in the BS information. In this way, terminal 10 sends the Auth Request using channels available to printer 100, so that printer 100 can properly receive the Auth Request.
[0089] The Auth Req is a signal requesting authentication from the sending terminal 10. Specifically, terminal 10 first generates a shared key using terminal 10's private key (not shown) and printer 100's public key PKpr, and then generates encrypted data by encrypting a random value using the shared key. Then, terminal 10 sends the Auth Req to printer 100, which includes terminal 10's public key (not shown), the encrypted data, and terminal 10's Capability. Terminal 10's Capability includes a value indicating that it can only operate as a DPP-based Configurator.
[0090] When printer 100 receives an Auth Request from terminal 10 via the first I / F 116A at T200 (S110), it performs authentication of the encrypted data contained in the Auth Request (S110). Specifically, printer 100 generates a shared key using the public key of terminal 10 and the private key of printer 100 (not shown) contained in the Auth Request, and uses the shared key to decrypt the encrypted data. If the decryption of the encrypted data is successful, printer 100 determines that authentication has been successful and executes the processes from T202 onwards.
[0091] In T202, printer 100 sends an Auth Res, including printer 100's Capability, to terminal 10 via the first I / F 116A (S110). Printer 100's Capability includes a value indicating that it can operate only as a DPP-based Enrollee.
[0092] Terminal 10 receives an Auth Res from printer 100 at T202 (S40). This completes the DPP authentication process.
[0093] Printer 100 sends a Configuration Req to terminal 10 via the first I / F 116A at T204 (S110). Hereafter, Configuration will be referred to as "Config". Config Req is a signal requesting the transmission of a CO for the printer.
[0094] When terminal 10 receives a Config Request from printer 100 in T204, it generates a printer CO (S40). Specifically, terminal 10 first generates a printer Signed Connector (hereinafter referred to as "SC"), which is information that should be used by printer 100 to establish a Wi-Fi connection with AP6A. The printer SC includes, for example, AP information for AP6A (i.e., SSID "S1", PW "P1"). Terminal 10 then generates a printer CO including the printer SC, and T206 sends a Config Res including the printer CO to printer 100 (S40).
[0095] When printer 100 receives a Config Res containing the printer CO from terminal 10 via the first I / F 116A in T206 (S110), printer 100 stores the printer CO contained in the Config Res in memory 134 of printer 100 in T208 (S110). This completes the DPP configuration.
[0096] Printer 100 establishes a Wi-Fi connection with AP6A via the first I / F 116A by performing DPP-based Network Access with AP6A at T210 (S110). During Network Access, various communications are performed between printer 100 and AP6A, and in the process of these communications, the SSID "S1" and PW "P1" included in the printer CO stored at T208 are used. This completes the DPP-based Network Access.
[0097] As shown in Case A above, once a Wi-Fi connection is established between the printer 100 and AP6A, a state is created where both the terminal 10 and the printer 100 have established a Wi-Fi connection with AP6A. In this case, the terminal 10 can send print data representing the image to be printed to the printer 100 via AP6A. The printer 100 can then print the image represented by the print data.
[0098] (Case B-2; Figure 7) Next, referring to Figure 7, we will explain Case B-2, in which a Wi-Fi connection is established between printer 100 and AP6B using a temporary connection, following the standard Wi-Fi method. Figure 7 is a continuation of Figure 5.
[0099] In Figure 7, first, the same process as in Figure 6 (T150-T170) is performed. At T272, terminal 10 accepts the user's selection of the SSID "S2" included in the connection selection screen SC1 (S24). Terminal 10 determines that the selected SSID "S2" does not match the SSID included in the AP information obtained at T130 (NO at S30). In this case, at T274, terminal 10 displays the input screen SC2 (S50). The input screen SC2 includes the SSID "S2" selected at T272, a password input area, an OK button, and a Cancel button. At T276, terminal 10 accepts the user's input of the PW "P2" for AP6B identified by SSID "S2", and at T278, accepts the selection of the OK button (S52). In this case, terminal 10 uses a temporary connection on T280 to send a connection instruction to printer 100 that includes the SSID "S2" and PW "P2" (S60).
[0100] At T280, the printer 100 uses a temporary connection to receive a connection instruction from terminal 10 via the second I / F 116B, which includes the SSID "S2" and PW "P2" (NO at S102). In this case, at T282, the printer 100 uses the SSID "S2" and PW "P2" included in the connection instruction to establish a Wi-Fi connection with AP6B (S130).
[0101] When terminal 10 sends a connection instruction using the temporary connection at T280, it sends a disconnection request to printer 100 using the temporary connection at T284.
[0102] When printer 100 receives a disconnection request from terminal 10 via the second I / F 116B using a temporary connection at T286, it stops SoftAP at T290. This disconnects the temporary connection between printer 100 and terminal 10.
[0103] (Case B-3; Figure 8)
[0104] Next, referring to Figure 8, we will explain another case B-3 in which a Wi-Fi connection is established between printer 100 and AP6B according to the normal Wi-Fi method using a temporary connection. Figure 8 is a continuation of Figure 5.
[0105] Printer 100 broadcasts a Probe request via the first I / F 116A at T350 (S100). In this case, the Probe request does not reach AP6A but reaches AP6B. Therefore, printer 100 receives a Probe response only from AP6B (S100).
[0106] The processing for T360-T362 is the same as the processing for T160-T162 in Figure 6. However, in this case, the query response includes only one SSID, "S2".
[0107] When terminal 10 receives a response from printer 100 using a temporary connection in T362 (YES in S20), it displays connection selection screen SC3 in T370 (S22). Connection selection screen SC3 contains only one SSID, "S2".
[0108] Terminal 10 accepts the user's selection of the SSID "S2" included in the connection selection screen SC3 at T372 (NO at S30). Subsequently, the same process as T274~T290 in Figure 7 is executed. This establishes a Wi-Fi connection between printer 100 and AP6B according to the normal Wi-Fi method (S130).
[0109] As shown in Case B-3, if the selected SSID "S2" does not match the SSID "S1" included in the AP information obtained by T130, terminal 10 sends a connection instruction to printer 100 including AP6B's SSID "S2" and password "PW2" (see T280 in Figure 7, which is referenced in Figure 8). In this way, terminal 10 can properly establish a Wi-Fi connection between printer 100 and AP6B.
[0110] (Case C; Figure 9) Next, referring to Figure 9, we will explain Case C, in which printer 200 is used instead of printer 100. Printer 200 does not support the DPP method.
[0111] In Figure 9, the same processing as T102 in Figure 5 to T154 in Figure 6 is performed between each device 200, 10, and 6A. Then, at T460, terminal 10 uses a temporary connection to send an inquiry request to printer 200 (S16).
[0112] The processing of T460 and T462 is the same as the processing of T160 and T162 in Figure 6. However, the processing of T460 and T462 is performed by the printer 200. The query response also includes unsupported information indicating that the printer 200 does not support the DPP method, and information about the printer 200 (i.e., printer ID "BBB", capability information).
[0113] When terminal 10 receives an inquiry response from printer 200 using a temporary connection in T462, it displays connection selection screen SC4 in T470 (S22). Connection selection screen SC4 includes the printer ID "BBB" of printer 200, the capabilities information of printer 200, and two SSIDs "S1" and "S2".
[0114] Terminal 10 accepts the user's selection of SSID "S1" from the connection selection screen SC4 in T472 (S24). Terminal 10 determines that the selected SSID "S1" matches the SSID included in the AP information obtained in T130 (YES in S30), and determines in S462 that the received inquiry response does not contain DPP support information (NO in S32). In this case, terminal 10 displays the input screen SC5 in T474 (S50). The input screen SC5 includes the SSID "S1" selected in T472, a password input area, an OK button, and a Cancel button.
[0115] The subsequent processing of T476 to T490 is the same as that of T276 to T290 in Figure 7. However, in T476, the password "P1" for AP6A is input, and in T480, a connection instruction including the SSID "S1" and password "P1" is sent. As a result, a Wi-Fi connection is established between the printer 200 and AP6A.
[0116] (Effects of this embodiment) In this embodiment, terminal 10 receives BS information, including the printer's public key PKpr, from printer 100 by performing communication at or above the network layer of the OSI reference model (T184 in Figure 6). In this way, terminal 10 can securely receive the printer's public key PKpr because it performs communication at or above the network layer. As a result, a secure Wi-Fi connection can be established between printer 100 and AP6A.
[0117] Here, let's explain the limitations of OS36. When terminal 10 has established a Wi-Fi connection with AP6A via the first I / F16A (T192 in Figure 6), OS36 can perform communication with printer 100 according to the DPP method and send a printer CO to printer 100 to establish a Wi-Fi connection with AP6A (T206). On the other hand, when terminal 10 has not established a Wi-Fi connection with AP6A, OS36 cannot send a printer CO to printer 100 to establish a Wi-Fi connection with AP6A. Due to these limitations of OS36, in this embodiment, terminal 10 receives BS information from printer 100 using a temporary connection (T184), then disconnects the temporary connection (T186, T190), and re-establishes a Wi-Fi connection with AP6A (T192). For this reason, terminal 10 can properly send a printer CO to printer 100 while it has established a Wi-Fi connection with AP6A (T206). As a result, a Wi-Fi connection can be properly established between AP6A and printer 100.
[0118] Terminal 10 can establish a Wi-Fi connection between printer 100 and AP6A according to the DPP method by performing various communications with printer 100 according to the DPP method (T200~T206 in Figure 6) for printer 100 that supports the DPP method. Furthermore, for printer 200 that does not support the DPP method, terminal 10 can establish a Wi-Fi connection between printer 200 and AP6A by sending a connection command to printer 200 (T480 in Figure 9). In this way, terminal 10 can appropriately establish a Wi-Fi connection with AP6A for both printer 100 that supports the DPP method and printer 200 that does not.
[0119] Furthermore, in this embodiment, the printer 100 transmits BS information, including the printer's public key PKpr, to the terminal 10 by performing communication at or above the network layer of the OSI reference model (T184 in Figure 6). In this way, the printer 100 performs communication at or above the network layer, so it can securely transmit the printer's public key PKpr. For this reason, a secure Wi-Fi connection can be established between the printer 100 and the AP6A.
[0120] Furthermore, if printer 100 receives a Probe response from AP6A via the first I / F116A that includes information indicating that WPS is being executed (T12 in Figure 4), it establishes a Wi-Fi connection with AP6A according to the WPS method (T14). On the other hand, if printer 100 receives a Probe request from terminal 10 via the second I / F116B (T140 in Figure 5), it establishes a temporary connection with terminal 10 (T144) and uses the temporary connection to communicate BS information with terminal 10 (T184 in Figure 6). Subsequently, printer 100 communicates with terminal 10 via the first I / F116A according to the DPP method and establishes a Wi-Fi connection with AP6A according to the DPP method. In this way, the printer 100 switches between the first I / F 116A and the second I / F 116B depending on the purpose of communication, thereby enabling it to properly establish a Wi-Fi connection with AP6A.
[0121] (Correspondence) The correspondences regarding "terminal devices" are as follows: Terminal 10, Wi-Fi I / F 16, CPU 32, and printer 100 are examples of "terminal devices," "wireless interfaces," "computers," and "communication devices," respectively. AP6A and AP6B are examples of "target access points" and "access points different from the target access points," respectively. Setup operation is an example of "first prescribed operation." The public key PKpr of printer 100 is an example of a "bootstrapping key." The Wi-Fi connection established at T194 in Figure 6 and the Wi-Fi connection established at T144 in Figure 5 are examples of "first wireless connections" and "second wireless connections," respectively. Auth Req is an example of an "authentication request." The printer CO and AP6B information (i.e., SSID "S2" and PW "P2") are examples of "first connection information" and "second connection information," respectively. Connection selection screen SC1 is an example of a "selection screen." MAC address (MA) and DPP support information are examples of "identification information" and "feasibility information," respectively.
[0122] The processes S14, S35, and S38 in Figure 2 are examples of processes executed by the "First Establishment Unit," "Key Communication Execution Unit," and "Second Establishment Unit," respectively. The processes T200 and T206 in Figure 6 are examples of processes executed by the "Authentication Request Communication Unit" and "First Connection Information Transmission Unit," respectively. The process S12 in Figure 2 is an example of a process executed by the "Disconnection Unit." The process T170 in Figure 6 is an example of a process executed by the "First Display Control Unit" and "Second Display Control Unit." The processes S34 and S60 in Figure 2 are examples of processes executed by the "DPP Execution Request Transmission Unit" and "Second Connection Information Transmission Unit," respectively. The process T162 in Figure 6 is an example of a process executed by the "SSID Receiving Unit," "Availability Information Receiving Unit," and "Device Information Receiving Unit." The process T184 in Figure 6 is an example of a process executed by the "Channel Information Receiving Unit."
[0123] The correspondence regarding "communication devices" is as follows: The first I / F116A and the second I / F116B are examples of the "first wireless interface" and the "second wireless interface," respectively. Wi-Fi button operation is an example of the "second specified operation." AP6A and AP6B are examples of the "first access point" and the "second access point," respectively. The Probe request at T8 and the Probe response at T12 in Figure 4 are examples of the "first Probe request" and the "first Probe response," respectively. The Probe request at T140 and the Probe response at T142 in Figure 5 are examples of the "second Probe request" and the "second Probe response," respectively. The Wi-Fi connection at T14 in Figure 4, the Wi-Fi connection at T144 in Figure 5, and the Wi-Fi connection at T210 in Figure 6 are examples of the "first wireless connection," the "second wireless connection," and the "third wireless connection," respectively. Information indicating that WPS is running is an example of "information indicating automatic wireless connection." The printer CO is an example of "connection information."
[0124] The processes T8 and T14 in Figure 4 are examples of processes executed by the "First Probe Request Transmission Unit" and the "First Establishment Unit," respectively. The processes T142 and T144 in Figure 5 are examples of processes executed by the "Probe Response Transmission Unit" and the "Second Establishment Unit," respectively. The processes T184, T200, T206, and T210 in Figure 6 are examples of processes executed by the "Key Communication Execution Unit," the "Authentication Request Communication Unit," the "Connection Information Reception Unit," and the "Third Establishment Unit," respectively. The process T162 in Figure 6 is an example of processes executed by the "SSID Transmission Unit" and the "Device Information Transmission Unit." The processes T180, T181, T182, and T184 in Figure 6 are examples of processes executed by the "DPP Execution Request Reception Unit," the "First Transition Unit," the "Generation Unit," and the "Channel Information Transmission Unit," respectively. The process T6 in Figure 4 is an example of a process executed by the "Second Transition Unit."
[0125] Although specific examples of the present invention have been described in detail above, these are merely illustrative and do not limit the scope of the claims. The technology described in the claims includes various modifications and changes to the specific examples illustrated above. Modifications of the above embodiments are listed below.
[0126] (Modification 1) The Wi-Fi I / F 116 of printer 100 may support the WFD method. In this case, instead of starting SoftAP with S80 in Figure 3, printer 100 may transition to the Group Owner state of the WFD method. In this modification, the Group Owner is an example of a "master station".
[0127] (Modification 2) The printer 100, operating as a SoftAP, may be able to establish a Wi-Fi connection with the terminal 10 without using the password "P3". In this case, the application 38 on the terminal 10 does not need to have the printer 100's SSID "S3" and password "P3" stored in advance. In this modification, when the terminal 10 receives a Probe response including the SSID "S3" from the printer 100 at T142 in Figure 5, it may establish a Wi-Fi connection with the printer 100 at T144 without performing password authentication.
[0128] (Modification 3) In the initial state of Figure 5, terminal 10 does not need to have established a Wi-Fi connection with AP6A. In this case, the process of T132 can be omitted. In this modification, the "cutting section" can be omitted.
[0129] (Modification 4) The printer 100 does not need to perform the processes T150 to T154 in Figure 6. In this case, the inquiry response T162 does not include the SSID. Therefore, the process T170 is also not performed. In this modification, the "SSID receiving unit" and the "SSID transmitting unit" can be omitted.
[0130] (Modification 5) If the answer is NO at S30 in Figure 2, the process in Figure 2 may be terminated without proceeding to S50. In this modification, the "second connection information transmission unit" can be omitted.
[0131] (Modification 6) In step S22 of Figure 2, terminal 10 does not need to prioritize the display of the target SSID over other SSIDs. In this modification, the "first display control unit" can be omitted.
[0132] (Variation 7) In S22 of Figure 2, terminal 10 may display only the target SSID out of two or more SSIDs on the connection selection screen. This variation is also an example of "prioritized display". "Prioritized display" may also be achieved by the following other variations (1) to (3): (1) The target SSID is displayed in a selectable manner, and the other SSIDs are displayed in a non-selectable manner (so-called grayed out). (2) The target SSID is displayed in a larger size than the other SSIDs. (3) The target SSID is displayed in a different color than the other SSIDs.
[0133] (Modification 8) In Figure 6, at T184, terminal 10 may, instead of receiving BS information including the public key PKpr of printer 100, send BS information including terminal 10's public key to printer 100. In this case, instead of the process at T200 in which terminal 10 sends an Auth Req to printer 100, the process in which printer 100 sends an Auth Req to terminal 10 is executed. Generally speaking, the "key communication execution unit" of the "terminal device" may receive the bootstrapping key of the communication device from the communication device, as in the above embodiment, or it may send the bootstrapping key of the terminal device to the communication device, as in this modification. Also, the "key communication execution unit" of the "communication device" may send the bootstrapping key of the communication device to the terminal device, as in the above embodiment, or it may receive the bootstrapping key of the terminal device from the terminal device, as in this modification.
[0134] (Modification 9) The public key PKpr does not have to be information obtained using the MAC address MA of printer 100, but may be information obtained using, for example, the serial number or printer ID of printer 100. In other words, the "identification information" can be any information used to identify printer 100. In another modification, the public key PKpr does not have to be information obtained using the identification information of printer 100.
[0135] (Modification 10) The printer 100 may always operate in the DPPON state. In this modification, the "DPP execution request transmission unit," the "DPP execution request reception unit," and the "first transition unit" are optional.
[0136] (Modification 11) Printer 100 may transmit BS information that does not include channel information CI to terminal 10 at T184 in Figure 6. For example, printer 100 may transmit channel information CI to terminal 10 at T162. That is, the timing of the processing performed by the "channel information receiving unit" and the "channel information transmitting unit" is not limited to the form of the above embodiment. In another modification, printer 100 does not need to transmit channel information CI to terminal 10. In this modification, the "channel information receiving unit" and the "channel information transmitting unit" can be omitted.
[0137] (Modification 12) Printer 100 may send an inquiry response to terminal 10 in T162 of Figure 6 that does not include the printer ID "AAA" and capability information. In this modification, the "device information receiving unit," "second display control unit," and "device information transmitting unit" are optional.
[0138] (Modification 13) In step T162 of Figure 6, the printer 100 may send a response to the terminal 10 that does not include information indicating that the printer 100 supports the DPP method. In this case, the process in S32 of Figure 2 can be omitted, and if the answer in S30 is YES, the process proceeds to S34. In this modification, the "approval / rejection information receiving unit" can be omitted.
[0139] (Modification 14) If the answer is NO in S32 of Figure 2, the process in Figure 2 may be terminated without proceeding to S50. In this modification, the "second connection information transmission unit" can be omitted.
[0140] (Modification 15) The printer 100 may store the public key PKpr in advance from the time of shipment. In this modification, the "generation unit" can be omitted.
[0141] (Modification 16) The printer 100 may always operate as the base station (i.e., SoftAP) of the Wi-Fi network. In this modification, the "second transition section" is optional.
[0142] (Modification 17) After receiving a Wi-Fi button press, the printer 100 may allow the user to choose whether to establish a Wi-Fi connection according to the DPP method or according to the normal Wi-Fi method. If the user chooses to establish a Wi-Fi connection according to the DPP method, the printer 100 may start SoftAP. In this modification, the operation of choosing to establish a Wi-Fi connection according to the DPP method is an example of the "second predetermined operation".
[0143] (Modification 18) In each of the above embodiments, the processes shown in Figures 2 to 9 are implemented by software (e.g., application 38, program 136), but at least one of these processes may be implemented by hardware such as a logic circuit.
[0144] Furthermore, the technical elements described herein or in the drawings demonstrate technical usefulness individually or in various combinations, and are not limited to the combinations described in the claims at the time of filing. In addition, the technologies illustrated herein or in the drawings achieve multiple objectives simultaneously, and achieving even one of these objectives constitutes technical usefulness in itself. [Explanation of symbols]
[0145] 2: Communication system, 10: Terminal, 12, 112: Operation unit, 14, 114: Display unit, 16, 116: Wi-Fi interface, 16A, 116A: First I / F, 16B, 116B: Second I / F, 30, 130: Control unit, 32, 132: CPU, 34, 134: Memory, 36: OS program, 38: Application, 61, 62: WPS button, 100, 200: Printer, 113: Wi-Fi button, 118: Print execution unit, 136: Program
Claims
1. A program for an application for a terminal device, The aforementioned terminal device is A wireless interface for performing wireless communication in accordance with the Wi-Fi standard, A memory for storing access point information, wherein the access point information is information for establishing a first wireless connection with a target access point, and the memory and Equipped with a computer, The aforementioned application program controls the computer as follows: A first establishment unit that establishes a second wireless connection with a communication device via the wireless interface, wherein the second wireless connection is a connection in which the communication device operates as a master station and the terminal device operates as a slave station, When the second wireless connection is established with the communication device, a key communication execution unit executes the communication of the bootstrapping key of the terminal device or the communication device with the communication device by using the second wireless connection and performing communication at or above the network layer of the OSI (Open Systems Interconnection) reference model via the wireless interface, If the second wireless connection is disconnected after the bootstrapping key communication has been performed with the communication device, the second establishment unit establishes the first wireless connection with the target access point via the wireless interface using the access point information in the memory. When the first wireless connection is established with the target access point, an authentication request communication unit executes communication of the authentication request, which is in accordance with the Wi-Fi standard's DPP (Device Provisioning Protocol) method and utilizes the bootstrapping key, with the communication device via the wireless interface. When the authentication request communication is performed with the communication device, a first connection information transmission unit transmits first connection information in accordance with the DPP method to the communication device via the wireless interface, wherein the first connection information is information for establishing a wireless connection between the communication device and the target access point. An application program that functions as such.
2. The aforementioned application program further uses the computer, When the first wireless connection is established with the target access point via the wireless interface, and a first predetermined operation is received from the user, the device functions as a disconnection unit to disconnect the first wireless connection. The application program according to claim 1, wherein the first establishment unit establishes the second wireless connection with the communication device after the first wireless connection has been disconnected.
3. The access point information includes the target SSID, which is an SSID (abbreviation for Service Set Identifier) that identifies the target access point. The aforementioned application program further uses the computer, Using the second wireless connection described above, the SSID receiving unit functions to receive one or more SSIDs from the communication device via the wireless interface, which identify one or more access points on which the communication device can establish a wireless connection. The key communication execution unit performs the bootstrapping key communication with the communication device when the one or more SSIDs include the target SSIDs included in the access point information in the memory. The application program according to claim 1 or 2, wherein if one or more of the SSIDs do not include the target SSIDs included in the access point information in the memory, the communication of the bootstrapping key is not executed.
4. The aforementioned application program further uses the computer, The application program according to claim 3, wherein, when one or more SSIDs do not include the target SSID included in the access point information in the memory, a second connection information transmission unit transmits a second connection information to the communication device via the wireless interface using the second wireless connection, wherein the second connection information is information for establishing a wireless connection between the communication device and an access point different from the target access point.
5. The terminal device further includes a display unit, The access point information includes the target SSID, which is an SSID (abbreviation for Service Set Identifier) that identifies the target access point. The aforementioned application program further uses the computer, Using the second wireless connection described above, an SSID receiving unit receives from the communication device via the wireless interface two or more SSIDs that identify two or more access points on which the communication device can establish a wireless connection, including the target SSID. A first display control unit that causes the display unit to display a selection screen for selecting one SSID from the two or more SSIDs, wherein the first display control unit displays the target SSID with priority over other SSIDs on the selection screen, An application program according to any one of claims 1 to 4, which functions as such.
6. The key communication execution unit, using the second wireless connection, receives the bootstrapping key of the communication device from the communication device via the wireless interface. The application program according to any one of claims 1 to 5, wherein the authentication request communication unit transmits the authentication request to the communication device via the wireless interface when the first wireless connection is established with the target access point.
7. The application program according to claim 6, wherein the bootstrapping key is information obtained using the identification information of the communication device.
8. The aforementioned application program further uses the computer, An application program according to claim 6 or 7, comprising a DPP execution request transmission unit that transmits a DPP execution request to the communication device via the wireless interface using the second wireless connection, wherein the DPP execution request is a request to transition the state of the communication device from a non-responsive state to a responsive state, the non-responsive state is a state in which the communication device is unable to transmit an authentication response to the authentication request, and the responsive state is a state in which the communication device is able to transmit the authentication response.
9. The aforementioned application program further uses the computer, Using the second wireless connection described above, the device functions as a channel information receiving unit that receives channel information indicating one or more channels available to the communication device from the communication device via the wireless interface. The application program according to any one of claims 6 to 8, wherein the authentication request communication unit transmits the authentication request to the communication device using one of the one or more wireless channels indicated by the channel information.
10. The terminal device further includes a display unit, The aforementioned application program further uses the computer, A device information receiving unit that uses the second wireless connection described above to receive device information related to the communication device from the communication device via the wireless interface, A second display control unit that displays the device information on the display unit, An application program according to any one of claims 1 to 9, which functions as such.
11. The aforementioned application program further uses the computer, Using the second wireless connection, the device functions as a compatibility information receiving unit that receives compatibility information from the communication device via the wireless interface, indicating whether or not the communication device supports the DPP method. The key communication execution unit, when the feasibility information indicates that the communication device supports the DPP method, performs the bootstrapping key communication with the communication device. The application program according to any one of claims 1 to 10, wherein the communication of the bootstrapping key is not executed if the feasibility information does not indicate that the communication device supports the DPP method.
12. The aforementioned application program further uses the computer, The application program according to claim 11, wherein, when the feasibility information does not indicate that the communication device supports the DPP method, a second connection information transmitting unit transmits a second connection information to the communication device via the wireless interface using the second wireless connection, wherein the second connection information is information for establishing a wireless connection between the communication device and an access point different from the target access point.
13. A terminal device, A wireless interface for performing wireless communication in accordance with the Wi-Fi standard, A memory for storing access point information, wherein the access point information is information for establishing a first wireless connection with a target access point, and the memory and Computers and, A first establishment unit that establishes a second wireless connection with a communication device via the wireless interface, wherein the second wireless connection is a connection in which the communication device operates as a master station and the terminal device operates as a slave station, When the second wireless connection is established with the communication device, a key communication execution unit executes the communication of the bootstrapping key of the terminal device or the communication device with the communication device by using the second wireless connection and performing communication at or above the network layer of the OSI (Open Systems Interconnection) reference model via the wireless interface, If the second wireless connection is disconnected after the bootstrapping key communication has been performed with the communication device, the second establishment unit establishes the first wireless connection with the target access point via the wireless interface using the access point information in the memory. When the first wireless connection is established with the target access point, an authentication request communication unit executes communication of the authentication request, which is in accordance with the Wi-Fi standard's DPP (Device Provisioning Protocol) method and utilizes the bootstrapping key, with the communication device via the wireless interface. When the authentication request communication is performed with the communication device, a first connection information transmission unit transmits first connection information in accordance with the DPP method to the communication device via the wireless interface, wherein the first connection information is information for establishing a wireless connection between the communication device and the target access point. A terminal device equipped with the following features.
14. A communication device, A first wireless interface for performing wireless communication in accordance with the Wi-Fi standard, A second wireless interface for performing wireless communication in accordance with the Wi-Fi standard, A first Probe request transmission unit that repeatedly transmits a first Probe request via the first wireless interface when a first predetermined operation is received from the user, When the first Probe request is transmitted and a first Probe response containing information indicating an automatic wireless connection is received from the first access point via the first wireless interface, a first establishment unit establishes a first wireless connection with the first access point via the first wireless interface, A Probe response transmission unit transmits a second Probe response to the terminal device via the second wireless interface when the first Probe request is transmitted but the first Probe response is not received via the first wireless interface, and a second Probe request is received from the terminal device via the second wireless interface. A second establishment unit establishes a second wireless connection with the terminal device via the second wireless interface when the second Probe response is transmitted to the terminal device, wherein the second wireless connection is a connection for which the communication device operates as a master station and the terminal device operates as a slave station, When the second wireless connection is established with the terminal device, a key communication execution unit executes communication of the bootstrapping key of the terminal device or the communication device with the terminal device by using the second wireless connection and performing communication at or above the network layer of the OSI (Open Systems Interconnection) reference model via the second wireless interface, After the bootstrapping key communication is performed with the terminal device, an authentication request communication unit executes, via the first wireless interface, an authentication request in accordance with the Wi-Fi standard's DPP (Device Provisioning Protocol) method, wherein the bootstrapping key is used in the authentication request, with the terminal device. When the authentication request communication is performed with the terminal device, a connection information receiving unit receives connection information in accordance with the DPP method from the terminal device via the first wireless interface. When the connection information is received from the terminal device, a third establishment unit establishes a third wireless connection with the first access point via the first wireless interface using the connection information. A communication device equipped with the following features.
15. The aforementioned communication device further, The device includes an SSID transmission unit that, using the second wireless connection, transmits one or more SSIDs to the terminal device via the second wireless interface, which identify one or more access points on which the communication device can establish a wireless connection. The communication device according to claim 14, wherein the connection information is information for establishing a third wireless connection with the first access point, which is identified by one SSID selected by the user of the terminal device from among the one or more SSIDs.
16. The key communication execution unit uses the second wireless connection to transmit the bootstrapping key of the communication device to the terminal device via the second wireless interface. The communication device according to claim 14 or 15, wherein the authentication request communication unit receives the authentication request from the terminal device via the first wireless interface.
17. The aforementioned communication device further, The communication device according to claim 16, further comprising a generation unit that generates the bootstrapping key of the communication device when the second wireless connection is established with the terminal device.
18. The communication device according to claim 16 or 17, wherein the bootstrapping key is information obtained using the identification information of the communication device.
19. The aforementioned communication device further, A DPP execution request receiving unit that receives a DPP execution request from the terminal device via the second wireless interface using the second wireless connection, wherein the DPP execution request is a request to change the state of the communication device from a non-responsive state to a responsive state, the non-responsive state is a state in which the communication device is unable to transmit an authentication response to the authentication request, and the responsive state is a state in which the communication device is able to transmit the authentication response, A first transition unit that, when the DPP execution request is received from the terminal device, transitions the state of the communication device from the non-responding state to the responding state, A communication device according to any one of claims 16 to 18, comprising:
20. The aforementioned communication device further, The communication device includes a channel information transmission unit that uses the second wireless connection to transmit channel information to the terminal device via the second wireless interface, indicating one or more wireless channels available to the communication device. The communication device according to any one of claims 16 to 19, wherein the authentication request communication unit receives the authentication request from the terminal device using one of the one or more wireless channels indicated by the channel information.
21. The aforementioned communication device further, A communication device according to any one of claims 14 to 20, comprising a device information transmission unit that transmits device information related to the communication device to the terminal device via the second wireless interface using the second wireless connection, wherein the device information is displayed on the display unit of the terminal device in response to the device information being received by the terminal device.
22. The aforementioned communication device further, The system includes a second transition unit that, when a second predetermined operation is received from the user, transitions the state of the communication device from a non-master state (where it does not operate as a master station) to a master state (where it operates as a master station), The communication device according to any one of claims 14 to 21, wherein the second establishment unit establishes the second wireless connection with the terminal device after the state of the communication device has transitioned to the master station state.