WO2014188686A1 - 無線接続認証方法及びサーバ - Google Patents

無線接続認証方法及びサーバ Download PDF

Info

Publication number
WO2014188686A1
WO2014188686A1 PCT/JP2014/002579 JP2014002579W WO2014188686A1 WO 2014188686 A1 WO2014188686 A1 WO 2014188686A1 JP 2014002579 W JP2014002579 W JP 2014002579W WO 2014188686 A1 WO2014188686 A1 WO 2014188686A1
Authority
WO
WIPO (PCT)
Prior art keywords
access point
wireless
wireless communication
message
code
Prior art date
Legal status (The legal status is an assumption and is not a legal conclusion. Google has not performed a legal analysis and makes no representation as to the accuracy of the status listed.)
Ceased
Application number
PCT/JP2014/002579
Other languages
English (en)
French (fr)
Inventor
勇士 大崎
武司 中山
昌明 原田
国男 中務
Current Assignee (The listed assignees may be inaccurate. Google has not performed a legal analysis and makes no representation or warranty as to the accuracy of the list.)
Panasonic Intellectual Property Corp of America
Original Assignee
Panasonic Intellectual Property Corp of America
Priority date (The priority date is an assumption and is not a legal conclusion. Google has not performed a legal analysis and makes no representation as to the accuracy of the date listed.)
Filing date
Publication date
Application filed by Panasonic Intellectual Property Corp of America filed Critical Panasonic Intellectual Property Corp of America
Priority to US14/415,361 priority Critical patent/US9832640B2/en
Priority to CN201480001902.5A priority patent/CN104488302B/zh
Priority to JP2014547212A priority patent/JP6244310B2/ja
Publication of WO2014188686A1 publication Critical patent/WO2014188686A1/ja
Anticipated expiration legal-status Critical
Ceased legal-status Critical Current

Links

Images

Classifications

    • HELECTRICITY
    • H04ELECTRIC COMMUNICATION TECHNIQUE
    • H04WWIRELESS COMMUNICATION NETWORKS
    • H04W12/00Security arrangements; Authentication; Protecting privacy or anonymity
    • H04W12/06Authentication
    • HELECTRICITY
    • H04ELECTRIC COMMUNICATION TECHNIQUE
    • H04WWIRELESS COMMUNICATION NETWORKS
    • H04W48/00Access restriction; Network selection; Access point selection
    • H04W48/20Selecting an access point
    • HELECTRICITY
    • H04ELECTRIC COMMUNICATION TECHNIQUE
    • H04WWIRELESS COMMUNICATION NETWORKS
    • H04W12/00Security arrangements; Authentication; Protecting privacy or anonymity
    • H04W12/60Context-dependent security
    • H04W12/69Identity-dependent
    • H04W12/73Access point logical identity
    • HELECTRICITY
    • H04ELECTRIC COMMUNICATION TECHNIQUE
    • H04WWIRELESS COMMUNICATION NETWORKS
    • H04W84/00Network topologies
    • H04W84/02Hierarchically pre-organised networks, e.g. paging networks, cellular networks, WLAN [Wireless Local Area Network] or WLL [Wireless Local Loop]
    • H04W84/10Small scale networks; Flat hierarchical networks
    • H04W84/12WLAN [Wireless Local Area Networks]

Definitions

  • the present invention relates to a wireless connection authentication method and a server.
  • a user When using a wireless LAN, a user needs to set wireless parameters such as a network identifier (ESSID), a frequency channel, an encryption method, an encryption key, an authentication method, and an authentication key for the wireless communication device. Since these setting operations are complicated, there is a method for automatically setting wireless parameters between terminals (see, for example, Patent Document 1).
  • ESSID network identifier
  • Patent Document 1 a method for automatically setting wireless parameters between terminals.
  • an object of the present invention is to provide a wireless connection authentication method in which a user can perform wireless connection authentication with a simple operation.
  • a wireless connection authentication method is a wireless connection authentication method in a server that performs wireless connection authentication for establishing communication between a first wireless communication apparatus and a wireless access point, and the first wireless communication
  • a determination step of determining the same wireless access point as a connection destination access point that is a connection destination wireless access point of the first wireless communication device, the connection destination access point, and the first access point An authentication processing step for performing processing for performing wireless connection authentication with the wireless communication device.
  • a wireless connection authentication method is a wireless connection authentication method for performing wireless connection authentication between a first wireless communication apparatus and a wireless access point, wherein the first wireless communication apparatus includes a first message. Transmitting a first message to the first wireless access point, and a second message including first access point information indicating that the first wireless access point that has received the first message indicates the first wireless access point. A second message transmission step of transmitting to the server; and a second wireless communication device that has already completed wireless connection authentication with a second wireless access point that is the same as or different from the first wireless access point, A third message transmitting step for transmitting to the wireless access point; and the second message receiving the third message.
  • a fourth message transmission step in which the access point transmits a fourth message including second access point information indicating the second wireless access point to the server; and the server indicates the first message indicated by the first access point information.
  • a determination step of determining the same wireless access point as a connection destination access point that is a connection destination wireless access point of the first wireless communication device; and the connection destination access point and the first wireless communication device are wirelessly connected
  • an authentication step for performing authentication is performed.
  • the present invention can provide a wireless connection authentication method in which a user can perform wireless connection authentication with a simple operation.
  • FIG. 1 is a diagram illustrating a configuration example of a communication system according to the first embodiment.
  • FIG. 2 is a block diagram illustrating a configuration example of the wireless communication apparatus according to the first embodiment.
  • FIG. 3 is a block diagram illustrating a configuration example of an access point in the first embodiment.
  • FIG. 4 is a block diagram illustrating a configuration example of the server in the first embodiment.
  • FIG. 5 is a block diagram illustrating a configuration example of a wireless communication apparatus that has already established communication with an access point in the first embodiment.
  • FIG. 6 is a sequence diagram of account authentication processing in the first embodiment.
  • FIG. 7 is a sequence diagram of account authentication processing in the first embodiment.
  • FIG. 8 is a diagram for explaining an operation example for a network connection request in the first embodiment.
  • FIG. 1 is a diagram illustrating a configuration example of a communication system according to the first embodiment.
  • FIG. 2 is a block diagram illustrating a configuration example of the wireless communication apparatus according to the first embodiment.
  • FIG. 9 is a diagram illustrating an example of information stored in the wireless communication device according to the first embodiment.
  • FIG. 10 is a diagram illustrating a configuration example of a connection request message according to the first embodiment.
  • FIG. 11 is a diagram illustrating a configuration example of a connection request message in the first embodiment.
  • FIG. 12 is a diagram illustrating a state in which the connection request message is transmitted in the first embodiment.
  • FIG. 13 is a diagram illustrating an example of information stored in the server according to the first embodiment.
  • FIG. 14 is a diagram for describing an operation example for a network participation confirmation request in the first embodiment.
  • FIG. 15 is a diagram illustrating a configuration example of a participation confirmation message in the first embodiment.
  • FIG. 16 is a diagram illustrating an example of an authentication code input operation according to the first embodiment.
  • FIG. 17 is a diagram illustrating a configuration example of an authentication code information message in the first embodiment.
  • FIG. 18 is a diagram illustrating a configuration example of a PIN code information message in the first embodiment.
  • FIG. 19 is a diagram illustrating a display example when the wireless connection authentication in the first embodiment is completed.
  • FIG. 20 is a flowchart showing processing of the wireless communication apparatus in the first embodiment.
  • FIG. 21 is a flowchart showing access point processing in the first embodiment.
  • FIG. 22 is a flowchart showing access point processing in the first embodiment.
  • FIG. 23 is a flowchart showing access point processing in the first embodiment.
  • FIG. 24 is a flowchart showing the processing of the server in the first embodiment.
  • FIG. 25 is a flowchart showing the processing of the server in the first embodiment.
  • FIG. 25 is a flowchart showing the processing of the server in the first embodiment.
  • FIG. 26 is a flowchart showing processing of the wireless communication apparatus that has already established communication with the access point in the first embodiment.
  • FIG. 27 is a sequence diagram of account authentication processing according to the second embodiment.
  • FIG. 28 is a sequence diagram of account authentication processing according to the second embodiment.
  • FIG. 29 is a flowchart showing access point processing in the second embodiment.
  • FIG. 30 is a flowchart illustrating access point processing according to the second embodiment.
  • FIG. 31 is a flowchart showing access point processing in the second embodiment.
  • FIG. 32 is a flowchart showing the processing of the server in the second embodiment.
  • FIG. 33 is a flowchart showing processing of the server in the second embodiment.
  • FIG. 34 is a flowchart showing processing of the wireless communication apparatus that has already established communication with the access point in the second embodiment.
  • FIG. 35 is a block diagram illustrating a configuration example of a wireless communication device according to the third embodiment.
  • FIG. 36 is a sequence diagram of account authentication processing according to the third embodiment.
  • FIG. 37 is a sequence diagram of account authentication processing according to the third embodiment.
  • FIG. 38 is a flowchart illustrating processing of the wireless communication device according to the third embodiment.
  • FIG. 39 is a flowchart showing processing of the wireless communication apparatus that has already established communication with the access point in the third embodiment.
  • FIG. 40 is a flowchart illustrating processing of the server in the embodiment.
  • Wi-Fi Protected Setup As a method for automatically setting wireless parameters, there is a wireless parameter automatic setting method called Wi-Fi Protected Setup (WPS) defined by an organization called Wi-Fi Alliance.
  • WPS Wi-Fi Protected Setup
  • a wireless parameter is provided from a registrar to an enrollee using a registration protocol.
  • the registrar is a device that manages wireless parameters and provides the wireless parameters to the enrollee.
  • An enrollee is a device that accepts wireless parameters provided by a registrar.
  • An EAP packet is a packet that can be communicated between a registrar and an enrollee without encryption and authentication.
  • a wireless communication device searches for a network formed by an access point and temporarily participates in the network.
  • the ESSID and the frequency channel in the access point and the wireless communication device match, but the encryption key and the authentication key do not match, so normal data communication using encryption and authentication cannot be performed. .
  • the access point and the wireless communication device transmit and receive messages using EAP packets according to the registration protocol.
  • the wireless parameter is provided from the access point to the wireless communication apparatus.
  • the wireless communication apparatus can perform data communication using encryption and authentication with the access point by newly setting the provided wireless parameter.
  • the setting method provided by WPS includes a push button method and a PIN (Personal Identification Number) code method.
  • the wireless parameter can be set automatically.
  • the wireless communication device is set to another access point. And may be connected unintentionally.
  • the wireless communication device is not connected to other access points unintentionally, but the user needs to select an access point and set a PIN code, which is troublesome for the user. is there.
  • Patent Literature 1 a user transmits a connection request to a desired access point, and the access point that has received the connection request transmits the user account of the user who transmitted the connection request to the account management server.
  • the account management server manages user accounts, generates a PIN code by authenticating the user, and gives a communication permission to the wireless communication apparatus by giving the PIN code to the access point.
  • the account management server generates the PIN code, so that the user can perform wireless connection setting without setting the PIN code.
  • the user needs to select a desired access point from access points existing in the network, which is a burden on the user.
  • a wireless communication device that is newly connected to an access point is authenticated using a wireless communication device that is already connected to the access point.
  • the wireless parameters of the wireless communication apparatus and the access point can be set without the user selecting the access point. Therefore, user operability can be improved.
  • a wireless connection authentication method is a wireless connection authentication method in a server that performs wireless connection authentication for establishing communication between a first wireless communication apparatus and a wireless access point, and the first wireless communication
  • a determination step of determining the same wireless access point as a connection destination access point that is a connection destination wireless access point of the first wireless communication device, the connection destination access point and the first access point An authentication processing step for performing processing for performing wireless connection authentication with the wireless communication device.
  • the user only needs to perform an operation for causing the first wireless communication apparatus to transmit the first message and an operation for causing the second wireless communication apparatus to transmit the third message.
  • the user can perform wireless connection authentication with a simple operation.
  • the wireless connection authentication method further includes a third reception step of receiving a first code unique to the first wireless communication device from the second wireless communication device, and the authentication processing step includes the first code.
  • a second code generation step of generating a second code used for wireless connection authentication between the first wireless communication apparatus and the connection destination access point, and transmitting the second code to the connection destination access point A transmission step.
  • each of the first message and the second message further includes a third code
  • the second code is generated using the first code and the third code. May be.
  • a wireless connection authentication method is a wireless connection authentication method for performing wireless connection authentication between a first wireless communication apparatus and a wireless access point, wherein the first wireless communication apparatus includes a first message. Transmitting a first message to the first wireless access point, and a second message including first access point information indicating that the first wireless access point that has received the first message indicates the first wireless access point. A second message transmission step of transmitting to the server; and a second wireless communication device that has already completed wireless connection authentication with a second wireless access point that is the same as or different from the first wireless access point, A third message transmitting step for transmitting to the wireless access point; and the second message receiving the third message.
  • a fourth message transmission step in which the access point transmits a fourth message including second access point information indicating the second wireless access point to the server; and the server indicates the first message indicated by the first access point information.
  • a determination step of determining the same wireless access point as a connection destination access point that is a connection destination wireless access point of the first wireless communication device; and the connection destination access point and the first wireless communication device are wirelessly connected
  • an authentication step for performing authentication is performed.
  • the user only needs to perform an operation for causing the first wireless communication apparatus to transmit the first message and an operation for causing the second wireless communication apparatus to transmit the third message.
  • the user can perform wireless connection authentication with a simple operation.
  • the wireless connection authentication method further includes an acquisition step in which the second wireless communication apparatus acquires a first code unique to the first wireless communication apparatus in response to a user operation, and the second wireless communication apparatus A first code transmission step of transmitting the first code to the server; and the server is used for wireless connection authentication between the first wireless communication device and the connection destination access point using the first code.
  • the wireless connection authentication method further includes a generation step in which the first wireless communication apparatus generates a fifth code, and each of the first message and the second message further includes the fifth code.
  • the second code generation step the second code is generated using the first code and the fifth code
  • the fourth code generation step the third code and the fifth code are used.
  • a fourth code may be generated.
  • the third message transmission step may be performed after the first message transmission step.
  • the wireless connection authentication method further includes a wireless signal transmission step in which the first wireless communication device transmits a wireless signal after the first message transmission step, and in the third message transmission step, the first message transmission step includes the first message transmission step.
  • the second wireless communication device may transmit the third message to the second wireless access point.
  • the first message transmission step may be performed after the third message transmission step.
  • a server is a server that performs wireless connection authentication for establishing communication between a first wireless communication device and a wireless access point, and is a first information transmitted from the first wireless communication device.
  • a first receiver that receives a second message that is transmitted by the first wireless access point according to one message and includes first access point information indicating the first wireless access point; and a first receiver that is the same as or different from the first wireless access point Second access point information indicating the second wireless access point transmitted by the second wireless access point in accordance with the third message transmitted from the second wireless communication apparatus that has already established communication with the two wireless access points.
  • a second receiver that receives the fourth message including the first wireless access point indicated by the first access point information.
  • the wireless access point is determined as a connection destination access point that is a connection destination wireless access point of the first wireless communication device, and wireless connection authentication between the connection destination access point and the first wireless communication device is performed.
  • An authentication processing unit that performs processing for performing the processing.
  • the user only needs to perform an operation for causing the first wireless communication apparatus to transmit the first message and an operation for causing the second wireless communication apparatus to transmit the third message.
  • the user can perform wireless connection authentication with a simple operation.
  • FIG. 1 is a diagram illustrating an example of a configuration of a typical communication system 100 according to the present embodiment.
  • the communication system 100 includes wireless communication devices 101 and 105, an access point 102, a server 103, and the Internet 104.
  • the wireless communication device 101 is a communication device having a wireless LAN communication function and a WPS function, for example, a personal computer or a home appliance having a wireless communication function.
  • the access point 102 has a wireless LAN and WPS function.
  • the server 103 has a function of managing an account (such as an ID and an authentication code) of a wireless communication device, and a function of authenticating the wireless communication device and giving communication permission to the wireless communication device.
  • the Internet 104 is a communication network that can be connected to computers all over the world.
  • the wireless communication device 105 is a communication device that has already established a connection with the access point 102 by a wired LAN or a wireless LAN, and is, for example, a personal computer, a mobile phone, a smartphone, or a tablet terminal.
  • a wireless LAN wireless local area network
  • the access point 102 and the server 103 are connected via the Internet 104.
  • the wireless communication device 101 and the wireless communication device 105 are connected to an infrastructure mode wireless network constructed by the access point 102.
  • the wireless communication apparatus 105 has already established a connection with the access point 102 and is permitted to connect to the Internet 104 using encryption.
  • the wireless communication device 101 and the access point 102 each set a PIN code. Then, the wireless communication apparatus 101 starts a wireless parameter automatic setting application. Then, the matching of the PIN codes held between the wireless communication apparatus 101 and the access point 102 is confirmed by the setting information notification protocol. Thereby, the wireless communication apparatus 101 can acquire a wireless parameter. That is, the PIN code is code information used for wireless parameter setting processing, or code information used for determining whether or not wireless parameters may be provided in the wireless parameter setting processing.
  • the wireless communication apparatus 101 and the access point 102 can transmit and receive various messages using the setting information notification protocol without encryption and authentication of the wireless LAN. Accordingly, the wireless communication apparatus 101 can communicate with only the access point 102 until the authentication is successful. Communication between the wireless communication apparatus 101 and the server 103 is performed by the access point 102 transferring a message. The wireless communication apparatus 101 can connect to the Internet 104 only when authentication with the server 103 is successful.
  • FIG. 2 is a block diagram illustrating an example of the configuration of the wireless communication apparatus 101 according to the present embodiment.
  • the wireless communication apparatus 101 illustrated in FIG. 2 includes a communication unit 201, a communication control unit 202, a device control unit 203, an interface processing unit 204, a wireless parameter setting processing unit 205, a code calculation unit 206, and a determination unit 207. And a storage unit 208.
  • the communication unit 201 performs wireless communication.
  • the communication control unit 202 controls the communication unit 201.
  • the device control unit 203 controls the overall operation of the wireless communication device 101.
  • the interface processing unit 204 controls various interfaces.
  • the wireless parameter setting processing unit 205 performs wireless parameter setting processing using a setting information notification protocol.
  • the code calculation unit 206 calculates various signals and hash values.
  • the determination unit 207 determines various processes.
  • the storage unit 208 stores wireless parameters, account information, IDs, authentication codes, and the like.
  • FIG. 3 is a block diagram showing an example of the configuration of the access point 102 in the present embodiment.
  • 3 includes a communication unit 301, a communication control unit 302, a device control unit 303, an interface processing unit 304, a wireless parameter setting processing unit 305, a determination unit 306, and a storage unit 307. Prepare.
  • the communication unit 301 performs wireless communication.
  • the communication control unit 302 controls the communication unit 301.
  • the device control unit 303 controls the operation of the entire device (access point 102).
  • the interface processing unit 304 controls various interfaces.
  • the wireless parameter setting processing unit 305 performs wireless parameter setting processing by a setting information notification protocol.
  • the determination unit 306 determines various processes.
  • the storage unit 307 stores wireless parameters, account information, a server IP (Internet Protocol) address, and the like.
  • FIG. 4 is a block diagram showing an example of the configuration of the server 103 in the present embodiment.
  • 4 includes a communication unit 401, a communication control unit 402, a device control unit 403, an interface processing unit 404, an authentication processing unit 405, a code calculation unit 406, a determination unit 407, and a storage unit. 408.
  • the communication unit 401 performs communication.
  • the communication control unit 402 controls the communication unit 401.
  • the device control unit 403 controls the operation of the entire device (server 103).
  • the interface processing unit 404 controls various interfaces.
  • the authentication processing unit 405 performs various authentication processes.
  • the code calculation unit 406 calculates various signals and hash values.
  • the determination unit 407 determines various processes.
  • the storage unit 408 stores wireless parameters, account information, an authentication code, and the like.
  • FIG. 5 is a block diagram showing an example of the configuration of the wireless communication apparatus 105 that has already established a connection with the access point 102 in this embodiment.
  • 2 includes a communication unit 501, a communication control unit 502, a device control unit 503, an interface processing unit 504, a wireless parameter setting processing unit 505, a determination unit 506, and a storage unit 507. And a display unit 508.
  • the communication unit 501 performs wireless communication.
  • the communication control unit 502 controls the communication unit 501.
  • the device control unit 503 controls the overall operation of the wireless communication device 105.
  • the interface processing unit 504 controls various interfaces.
  • a wireless parameter setting processing unit 505 performs wireless parameter setting processing by a setting information notification protocol.
  • the determination unit 506 determines various processes.
  • the storage unit 507 stores wireless parameters, account information, and the like.
  • the display unit 508 performs various displays.
  • 6 and 7 are sequence diagrams showing an account authentication sequence in the present embodiment.
  • FIG. 8 is a diagram illustrating an example of a user operation.
  • the user presses an operation button 651 that is provided in the wireless communication apparatus 101 (for example, a refrigerator) for performing network connection.
  • the wireless parameter automatic setting application is activated.
  • the wireless communication device 101 searches for a nearby wireless network (S102). Next, the wireless communication device 101 sequentially selects a plurality of searched wireless networks and participates in the selected wireless network. In this example, the wireless network of the access point 102 is selected, and the wireless communication apparatus 101 joins the wireless network of the access point 102 (S103). However, at this point, no common encryption key, authentication key, or the like is set for the wireless communication apparatus 101 and the access point 102. Therefore, the wireless communication apparatus 101 is in a state where it can communicate with the access point 102 only by a specific signal (such as a broadcast signal and an EAP packet) in the wireless network of the access point 102, and performs normal data communication using encryption and authentication. It is not possible.
  • various messages are transmitted and received between the wireless communication apparatus 101 and the access point 102 using EAP packets.
  • the wireless communication device 101 generates a random value (S104).
  • the wireless communication apparatus 101 transmits a connection request message 611 including a random value and an ID to the access point 102 (S105).
  • FIG. 9 is a diagram illustrating an example of information stored in the storage unit 208 included in the wireless communication apparatus 101. As illustrated in FIG. 9, the storage unit 208 stores an ID 661 and an authentication code 662.
  • ID 661 is an identifier for identifying the wireless communication apparatus 101, and is, for example, a model number, a serial number, or a combination thereof of the wireless communication apparatus 101.
  • the ID 661 may be an arbitrary number or combination of characters.
  • the authentication code 662 is an identifier for identifying the wireless communication apparatus 101, and is, for example, a model number, a serial number, or a combination thereof of the wireless communication apparatus 101.
  • the authentication code 662 may be an arbitrary number or combination of characters.
  • the ID 661 and the authentication code 662 are individually described here, only one of the ID 661 and the authentication code 662 may be used. In other words, the ID 661 and the authentication code 662 may be the same code (identifier).
  • FIG. 10 is a diagram illustrating a configuration example of the connection request message 611.
  • the connection request message 611 is a message for the wireless communication apparatus 101 to request the server 103 to connect to the network.
  • the connection request message 611 is a message for the wireless communication apparatus 101 to request the server 103 to connect to the access point 102.
  • the connection request message 611 includes the ID 661 stored in the storage unit 208 and the random value 663 generated in step S104.
  • connection request message 611 includes information other than the above as necessary (for example, information indicating the type of the message and information indicating the transmission source and destination of the message). Is not shown. Further, the point that these pieces of information are included is the same in various messages described later.
  • the access point 102 When the access point 102 receives the connection request message 611, the access point 102 generates the connection request message 612 by adding the access point information 664 to the received connection request message 611, and transmits the generated connection request message 612 to the server 103. (S106).
  • FIG. 11 is a diagram illustrating a configuration example of the connection request message 612.
  • the connection request message 612 includes an ID 661 and a random value 663 included in the connection request message 611, and access point information 664.
  • the access point information 664 is information indicating the access point that is the transmission source of the connection request message 612. Therefore, in this example, the access point information 664 indicates the access point 102.
  • the wireless communication apparatus 101 may generate the connection request message 611 including the access point information 664.
  • the access point information 664 indicates an access point to which the connection request message 611 is transmitted.
  • the server 103 When the server 103 receives the connection request message 612, the server 103 checks the validity of the ID 661 included in the received connection request message 612 (S107), and when the ID 661 is valid, the wireless communication apparatus 101 having the received ID 661. Are registered as terminals having a connection request to the access point 102 (S108).
  • steps S103 and S105 are performed for each of the plurality of access points.
  • the server 103 receives a plurality of connection request messages 612 via different access points. For example, as shown in FIG. 12, when there are an access point 102 (AP1) and an access point 102A (AP2) near the wireless communication apparatus 101, a connection request message 612 via the access point 102 and an access point The connection request message 612 via 102A is received by the server 103.
  • AP1 access point 102
  • AP2A access point 102A
  • information (ID 671, random value 672, and access point information 673) corresponding to the two connection request messages 612 is registered in the server 103 as shown in FIG.
  • the access points indicated by the access point information 673 are different.
  • the ID 671 and the random value 672 of the two connection request messages 612 are the same, but at least one of them may be different.
  • FIG. 14 is a diagram illustrating an example of a user operation.
  • the user selects an operation menu 652 for confirming network participation in the wireless communication apparatus 105 (for example, a smartphone). Thereby, the participation registration application is activated.
  • the wireless communication apparatus 105 transmits a participation confirmation message 613 to the access point 102 (S110).
  • the access point 102 receives the participation confirmation message 613
  • the access point 102 generates the participation confirmation message 614 by adding the access point information 665 to the participation confirmation message 613, and transmits the generated participation confirmation message 614 to the server 103 (S111). ).
  • FIG. 15 is a diagram illustrating a configuration example of the participation confirmation message 614.
  • the participation confirmation message 614 includes access point information 665.
  • the access point information 665 is information indicating the access point of the transmission source of the participation confirmation message 614. Therefore, in this example, the access point information 665 indicates the access point 102.
  • the wireless communication apparatus 105 may generate the participation confirmation message 613 including the access point information 665.
  • the access point information 665 indicates an access point to which the participation confirmation message 613 is transmitted.
  • the access point information 665 indicates the access point 102 with which the wireless communication apparatus 105 has already established communication.
  • the access point information 665 indicates the access point 102 to which the wireless communication apparatus 101 is connected.
  • the server 103 When the server 103 receives the participation confirmation message 614, the server 103 confirms whether there is a terminal that has a connection request to the access point 102. Specifically, the server 103 checks whether there is access point information 673 indicating the same access point as the access point indicated by the access point information 665 included in the participation confirmation message 614 (S112).
  • the server 103 uses the AP1 (access point) indicated by the access point information 665. 102) is determined as the connection destination of the wireless communication apparatus 101.
  • the server 103 transmits an authentication code request message 615A to the access point 102 determined as the connection destination (S113).
  • the access point 102 receives the authentication code request message 615A
  • the access point 102 transmits the authentication code request message 615B to the wireless communication apparatus 105 (S114).
  • the wireless communication device 105 When the wireless communication device 105 receives the authentication code request message 615B, the wireless communication device 105 generates an authentication code according to a user operation or the like (S115). For example, as shown in FIG. 16, the user inputs an authentication code into the input menu 653.
  • the input authentication code is a number or a character string unique to the wireless communication apparatus 101 and is the same as the authentication code 662 stored in the storage unit 208 of the wireless communication apparatus 101.
  • the user confirms an authentication code described in a housing of the wireless communication device 101 (for example, home appliance) or an instruction manual, and inputs the authentication code to the input menu 653.
  • the user may photograph a barcode or a two-dimensional barcode described in a case of the wireless communication device 101 or an instruction manual with the wireless communication device 105 (for example, a smartphone). Thereby, the wireless communication apparatus 105 can acquire the authentication code.
  • FIG. 17 is a diagram illustrating a configuration example of the authentication code information message 616A. As shown in FIG. 17, the authentication code information message 616A includes the authentication code 666 generated in step S115.
  • the access point 102 When the access point 102 receives the authentication code information message 616A, the access point 102 transmits an authentication code information message 616B including the authentication code 666 included in the authentication code information message 616A to the server 103 (S117).
  • the configuration example of the authentication code information message 616B is the same as the configuration example of the authentication code information message 616A shown in FIG.
  • the server 103 checks the validity of the authentication code 666 included in the received authentication code information message 616B (S118). When the authentication code 666 is valid, the server 103 includes the PIN code for setting the wireless parameter of the wireless communication apparatus 101 that is a terminal that has a connection request to the access point 102 in the connection request message 612. It generates using the random value 663 and the authentication code 666 included in the authentication code information message 616B (S119).
  • the server 103 transmits a PIN code information message 617 including the generated PIN code 667 to the access point 102 (S120).
  • the access point 102 activates the wireless parameter automatic setting application and sets the added PIN code 667 in the wireless parameter automatic setting application (S121).
  • the access point 102 transmits a PIN code generation completion message to the wireless communication apparatus 101 (S122).
  • the wireless communication apparatus 101 When receiving the PIN code generation completion message 618, the wireless communication apparatus 101 generates a PIN code using the random value generated in step S104 and the authentication code 662 stored in the storage unit 208 (S123). . Next, the wireless communication apparatus 101 sets the generated PIN code in the wireless parameter automatic setting application (S124). Next, the wireless communication apparatus 101 transmits a protocol start request message 619 to the access point 102 to start the setting information notification protocol (S125).
  • the access point 102 When the access point 102 receives the protocol start request message 619 from the wireless communication apparatus 101, the access point 102 transmits the protocol start message 620 to the wireless communication apparatus 101 (S126). Then, the wireless communication apparatus 101 and the access point 102 exchange protocol messages 621 according to the WPS registration protocol (S127).
  • the wireless communication apparatus 101 and the access point 102 only when both the wireless communication apparatus 101 and the access point 102 confirm that the PIN code set in the wireless communication apparatus 101 matches the PIN code set in the access point 102, the access point 102. Are transmitted to the wireless communication apparatus 101, and the transmitted wireless parameters are set in the wireless communication apparatus 101.
  • the access point 102 transmits a protocol end message 622 to the wireless communication apparatus 101 (S128), and transmits a WPS success message 623 to the server 103 (S129).
  • the server 103 receives the WPS success message 623, the server 103 performs processing for permitting the wireless communication apparatus 101 to connect to the Internet (S130).
  • the wireless communication apparatus 101 When the wireless communication apparatus 101 receives the protocol end message 622, the wireless communication apparatus 101 once leaves the network and uses the parameters acquired from the access point 102 to connect to the wireless network of the access point 102 again (S131).
  • the wireless communication apparatus 101 is set with an encryption key, an authentication key, and the like common to the access point 102. Therefore, the wireless communication apparatus 101 can perform normal data communication using encryption and authentication.
  • the server 103 transmits the connection permission message 624A to the access point 102 after performing the process of permitting the connection (S132).
  • the access point 102 transmits the connection permission message 624B to the wireless communication apparatus 105 (S133).
  • the wireless communication device 105 receives the connection permission message 624B, for example, the wireless communication device 105 displays a message 654 indicating that wireless connection authentication between the wireless communication device 101 and the access point 102 is completed as shown in FIG.
  • the communication system 100 performs wireless connection authentication between the wireless communication apparatus 101 and the access point 102.
  • the wireless communication apparatus 101 transmits a connection request message 611 to the first wireless access point (access point 102 or access point 102A) (S105).
  • the access point 102 (or access point 102A) that has received the connection request message 611 transmits a connection request message 612 including access point information 664 indicating the first wireless access point to the server 103 (S106).
  • the wireless communication apparatus 105 that has already completed wireless connection authentication with the second wireless access point (access point 102) that is the same as or different from the first wireless access point transmits a participation confirmation message 613 to the second wireless access point. (S110).
  • the second wireless access point that has received the participation confirmation message 613 transmits a participation confirmation message 614 including access point information 665 indicating the second wireless access point to the server 103 (S111).
  • the server 103 compares the first wireless access point indicated by the access point information 664 with the second wireless access point indicated by the access point information 665, and as a result, the first wireless access point and the second wireless access point are compared.
  • the same wireless access point is determined as a connection destination access point that is a connection destination wireless access point of the wireless communication apparatus 101 (S112).
  • connection destination access point and the wireless communication apparatus 101 perform wireless connection authentication (S125 to S128).
  • the server 103 transmits the participation confirmation message 613 transmitted from the wireless communication apparatus 105. Accordingly, the connection target wireless access point of the wireless communication apparatus 101 can be appropriately determined using the access point information 665 transmitted by the connection target wireless access point (access point 102).
  • the user only needs to perform an operation for causing the wireless communication apparatus 101 to transmit the connection request message 611 and an operation for causing the wireless communication apparatus 105 to transmit the participation confirmation message 613.
  • the user presses an operation button 651 provided on the wireless communication device 101 (refrigerator) as shown in FIG. 8, and then, as shown in FIG. 14, the operation menu 652 is displayed on the wireless communication device 105 (smartphone). Only a simple operation of selecting is required.
  • the wireless connection authentication method according to the present embodiment allows the user to perform wireless connection authentication with a simple operation.
  • the wireless communication device for example, home appliance
  • the access point may be arranged apart from each other.
  • buttons and the like provided on the access point cannot be easily operated.
  • a user's own smartphone may be operated, so that the user's trouble can be reduced.
  • the radio parameters of a terminal that is newly connected to the network are set using a terminal that has already established a connection with a desired access point.
  • the server 103 determines whether information indicating the same access point is included in a message transmitted from a terminal newly connected to the network and a terminal that has already established a connection with a desired access point. To do. Thereby, even when there are a plurality of access points capable of performing wireless communication, it is possible to prevent connection to an unintended access point. Further, since the user does not need to select an access point, user operability is improved.
  • the wireless communication device 105 acquires an authentication code 666 (first code) unique to the wireless communication device 101 in response to a user operation (S115).
  • the wireless communication device 105 transmits an authentication code 666 to the server 103 (S116 and S117).
  • the wireless communication apparatus 105 transmits an authentication code information message 616A (616B) including the authentication code 666 to the server 103 via the access point 102.
  • the server 103 uses the authentication code 666 to generate a PIN code 667 (second code) used for wireless connection authentication between the wireless communication apparatus 101 and the connection destination access point (access point 102) (S119). Next, the server 103 transmits the PIN code 667 to the access point 102 (S120).
  • a PIN code 667 second code used for wireless connection authentication between the wireless communication apparatus 101 and the connection destination access point (access point 102) (S119).
  • the server 103 transmits the PIN code 667 to the access point 102 (S120).
  • the wireless communication apparatus 101 generates a PIN code (fourth code) using the same authentication code 662 (third code) as the authentication code 666 (S123).
  • the wireless communication apparatus 101 and the access point 102 authenticate the wireless connection with the wireless communication apparatus 101 and the access point 102 according to whether the authentication code 662 and the authentication code generated by the wireless communication apparatus 101 are the same. (S125 to S128).
  • the same PIN code can be set safely and automatically in the wireless communication device 101 and the access point 102 in the wireless LAN.
  • two PIN codes are generated using the authentication code 662 held by the wireless communication apparatus 101 and the authentication code 666 input by the user to the wireless communication apparatus 105. Can be prevented from being mistakenly authenticated.
  • each of the connection request messages 611 and 612 further includes a random value 663.
  • the server 103 generates a PIN code 667 using the authentication code 666 and the random value 663 (S119).
  • the wireless communication apparatus 101 generates an authentication code using the authentication code 662 and the random value 663 (S123).
  • the set PIN code is generated using the random value and the authentication code, a different PIN code is generated for each setting. Thereby, safety can be improved. Further, since the authentication code is communicated only on the encrypted network, the security is high.
  • the wireless communication device 101 for example, home appliance
  • the wireless communication device 105 for example, a smartphone
  • FIG. 20 is a flowchart showing processing of the wireless communication apparatus 101 in the present embodiment. This process is started when the wireless communication apparatus 101 is connected to a wireless network constructed by the access point 102. At this point, no common encryption key, authentication key, or the like is set for the wireless communication apparatus 101 and the access point 102. Therefore, the wireless communication apparatus 101 can communicate with the access point 102 only with a specific signal (such as a broadcast signal and an EAP packet) in the wireless network of the access point 102, and performs normal data communication using encryption and authentication. Can't do it. Here, various messages are transmitted and received between the wireless communication apparatus 101 and the access point 102 using EAP packets.
  • a specific signal such as a broadcast signal and an EAP packet
  • the wireless communication apparatus 101 generates a random value 663 necessary for generating a PIN code (S201). Then, the wireless communication apparatus 101 transmits a connection request message 611 including the random value 663 and the ID 661 to the access point 102 (S202). After transmitting the connection request message 611, the wireless communication apparatus 101 waits until a PIN code generation completion message 618 is received from the access point 102 or a protocol failure message is received (S203 and S204). If the wireless communication apparatus 101 receives a protocol failure message (YES in S204), the wireless communication apparatus 101 ends this process.
  • the wireless communication apparatus 101 when the wireless communication apparatus 101 receives the PIN code generation completion message 618 (YES in S203), the wireless communication apparatus 101 generates a PIN code using the authentication code 662 (password) and the previously generated random value 663 (S205).
  • the method for generating the PIN code may be any method such as a method using a cryptographic algorithm or a hash algorithm.
  • the wireless communication device 101 After generating the PIN code, the wireless communication device 101 sets the PIN code in the wireless parameter automatic setting application (S206). Then, the wireless communication apparatus 101 executes the setting information notification protocol using the set PIN code (S207). In the setting information notification protocol, the enrollee and the registrar authenticate each other's legitimacy by determining whether or not their PIN codes match. Therefore, the enrollee can acquire wireless parameters from a registrar having the same PIN code.
  • the wireless communication apparatus 101 determines whether or not the setting information notification protocol has succeeded after the setting information notification protocol has ended (S208).
  • the success of the setting information notification protocol indicates that acquisition of the wireless parameter from the registrar holding the PIN code that matches the enrollee PIN code has been completed. If the setting information notification protocol has failed (NO in S208), the wireless communication apparatus 101 ends this process.
  • the wireless communication device 101 connects to the wireless network constructed by the access point 102 using the acquired wireless parameters (S209).
  • the wireless communication apparatus 101 is set with an encryption key, an authentication key, and the like that are common to the access point 102.
  • the wireless communication apparatus 101 can perform normal data communication using encryption and authentication.
  • FIG. 21, FIG. 22 and FIG. 23 are flowcharts showing processing of the access point 102 in the present embodiment.
  • This process is started when the wireless communication apparatus 101 that requests execution of wireless parameter automatic setting participates in the wireless network constructed by the access point 102.
  • no common encryption key, authentication key, or the like is set for the wireless communication apparatus 101 and the access point 102. Therefore, the wireless communication apparatus 101 can communicate with the access point 102 only with a specific signal (such as a broadcast signal and an EAP packet) in the wireless network of the access point 102, and performs normal data communication using encryption and authentication. Can't do it.
  • various messages are transmitted and received between the wireless communication apparatus 101 and the access point 102 using EAP packets.
  • the access point 102 waits to receive a connection request message 611 from the wireless communication apparatus 101 (S301).
  • the access point 102 receives the connection request message 611 from the wireless communication apparatus 101 (YES in S301)
  • the access point 102 receives the random value 663 and ID 661 included in the connection request message 611, and the access point information 664 indicating the access point 102.
  • the connection request message 612 including this is transmitted to the server 103 (S302).
  • the access point 102 After transmitting the connection request message 612, the access point 102 receives a participation confirmation message 613 from the wireless communication apparatus 105 that has already established a connection with the access point 102 or until it receives a rejection notification message from the server 103. Wait (S303 and S304).
  • the access point 102 When the access point 102 receives the rejection notification message (YES in S304), the access point 102 transmits a protocol failure message to the wireless communication device 101 (S305), and ends this process.
  • the wireless communication device 105 and the access point 102 since a common encryption key and authentication key are set in the wireless communication device 105 and the access point 102, the wireless communication device 105 and the access point 102 perform normal data communication using encryption and authentication. be able to.
  • the access point 102 When the access point 102 receives the participation confirmation message 613 from the wireless communication apparatus 105 (YES in S303), the access point 102 transmits a participation confirmation message 614 including access point information 665 indicating the access point 102 to the server 103 (S306). After transmitting the participation confirmation message 614, the access point 102 waits until an authentication code request message 615A is received from the server 103 or a rejection notification message is received (S307 and S308). When the access point 102 receives the rejection notification message (YES in S308), the access point 102 transmits a protocol failure message to the wireless communication device 101, transmits a rejection notification message to the wireless communication device 105 (S309), and ends this processing. .
  • the access point 102 When the access point 102 receives the authentication code request message 615A (YES in S307), the access point 102 transmits the authentication code request message 615B to the wireless communication device 105 (S310). After transmitting the authentication code request message 615B, the access point 102 waits until receiving an authentication code information message 616A including the authentication code 666 from the wireless communication apparatus 105 (S311).
  • the authentication code 666 is a number or a character string unique to the wireless communication apparatus 101.
  • the access point 102 When the access point 102 receives the authentication code information message 616A (YES in S311), the access point 102 transmits an authentication code information message 616B including the authentication code 666 included in the authentication code information message 616A to the server 103 (S312). After transmitting the authentication code information message 616B, the access point 102 waits until a PIN code information message 617 is received from the server 103 or a rejection notification message is received (S313 and S314). When the access point 102 receives the rejection notification message (YES in S314), the access point 102 transmits a protocol failure message to the wireless communication device 101, transmits a rejection notification message to the wireless communication device 105 (S315), and ends this processing. .
  • the access point 102 when the access point 102 receives the PIN code information message 617 (YES in S313), the access point 102 sets the PIN code 667 included in the PIN code information message 617 in the wireless parameter automatic setting application (S316). Then, the access point 102 transmits a PIN code generation completion message 618 to the wireless communication apparatus 101 (S317). Next, the access point 102 executes a setting information notification protocol with the wireless communication apparatus 101 using the set PIN code 667 (S318).
  • the access point 102 determines whether the setting information notification protocol is successful (S319).
  • the success of the setting information notification protocol indicates a case where the PIN code held by the registrar matches the PIN code held by the enrollee and the provision of wireless parameters from the registrar to the enrollee is completed.
  • the access point 102 transmits a WPS success message 623 to the server 103 (S320).
  • the access point 102 waits until a connection permission message 624A is received from the server 103 (S321).
  • the access point 102 receives the connection permission message 624A (YES in S321)
  • the access point 102 transmits the connection permission message 624B to the wireless communication device 105 (S322), and ends this process.
  • the access point 102 transmits a WPS failure message to the server 103 (S323). After transmitting the WPS failure message, the access point 102 waits until a connection failure message is received from the server 103 (S324). When the access point 102 receives the connection failure message (YES in S324), the access point 102 transmits the connection failure message to the wireless communication device 105 (S325), and ends this process.
  • FIG. 24 and 25 are flowcharts showing the processing of the server 103 in this embodiment.
  • the server 103 waits for reception of a connection request message 612 from the access point 102 (S401).
  • the server 103 receives the connection request message from the access point 102 (YES in S401)
  • the server 103 checks whether or not the ID 661 included in the connection request message 612 is a valid ID (S402).
  • the server 103 refers to the account management information stored in the storage unit 408, and determines that the received ID 661 is valid if the ID registered in advance as the valid ID matches the received ID 661.
  • the server 103 transmits a rejection notification message to the access point 102 (S416), and ends this process.
  • the server 103 registers the ID 661 of the wireless communication apparatus 101 that has transmitted the connection request message 611 (S403).
  • the server 103 waits until a participation confirmation message 614 is received from the access point 102 (S404).
  • the server 103 receives the participation confirmation message 614 (YES in S404)
  • the access point indicated by the access point information 665 included in the participation confirmation message 614 is indicated by the access point information 664 included in the connection request message 612. It is confirmed whether it is the same as the access point (S405).
  • the server 103 waits until receiving a participation confirmation message 614 from the access point 102 (S404). On the other hand, if the access points are the same, that is, if the participation confirmation message 614 has been transmitted from the access point 102 (YES in S405), the server 103 transmits an authentication code request message 615A to the access point 102 (S406).
  • the server 103 waits until the authentication code information message 616B is received from the access point 102 (S407).
  • the authentication code 666 included in the authentication code information message 616B is an authentication code associated with the ID for which the connection request has been made. It is confirmed whether or not (S408).
  • the server 103 refers to the account management information stored in the storage unit 408, and if the authentication code associated with the ID in advance matches the received authentication code 666, the received authentication code 666 is valid. to decide.
  • the authentication code is a code unique to the wireless communication apparatus 101, the validity of the wireless communication apparatus 105 can be confirmed by this processing.
  • the server 103 transmits a rejection notification message to the access point 102 (S416), and the process ends.
  • the server 103 uses the random value 663 included in the connection request message 612 and the authentication code 666 included in the authentication code information message 616B to use the PIN code. 667 is generated (S409).
  • the server 103 transmits a PIN code information message 617 including the generated PIN code 667 to the access point 102 (S410). After transmitting the PIN code information message 617, the server 103 waits for reception of a WPS success message 623 from the access point 102 or reception of a WPS failure message (S411 and S412).
  • the server 103 When the server 103 receives the WPS success message 623 (YES in S411), the server 103 performs processing for permitting the wireless communication device 101 to connect to the Internet 104 (S414). Next, the server 103 transmits a connection permission message 624A to the access point 102 (S415), and ends this process. If the server 103 receives a WPS failure message (YES in S412), the server 103 transmits a connection failure message to the access point 102 (S413), and ends this process.
  • FIG. 26 is a flowchart showing processing of the wireless communication apparatus 105 in the present embodiment. Note that a common encryption key, authentication key, and the like are already set in the wireless communication device 105 and the access point 102. Therefore, the wireless communication apparatus 105 can perform normal data communication using encryption and authentication in the wireless network of the access point 102.
  • the wireless communication apparatus 105 transmits a participation confirmation message 613 to the access point 102 (S501), and waits to receive an authentication code request message 615B from the access point 102 (S502).
  • the wireless communication device 105 When the wireless communication device 105 receives the authentication code request message 615B (YES in S502), the wireless communication device 105 generates an authentication code 666 in accordance with a user operation or the like (S503).
  • the authentication code 666 is a number or a character string unique to the wireless communication apparatus 101.
  • the wireless communication apparatus 105 transmits an authentication code information message 616A including the generated authentication code 666 to the access point 102 (S504).
  • the wireless communication apparatus 105 After transmitting the authentication code information message 616A, the wireless communication apparatus 105 waits to receive a connection permission message 624B, a rejection notification message, or a connection failure message from the access point 102 (S505, S506). And S507). When the wireless communication apparatus 105 receives the connection permission message 624B, the rejection notification message, or the connection failure message from the access point 102 (YES in S505, YES in S506, or YES in S507), this process is performed. Exit.
  • the outline of the configuration of the communication system 100 in the present embodiment and the outline of the configuration of the wireless communication apparatus 101, the access point 102, the server 103, and the wireless communication apparatus 105 that has already established communication with the access point 102 are as follows. These are the same as those of the first embodiment described with reference to FIGS. 1 to 5 and will not be described.
  • 27 and 28 are sequence diagrams showing the account authentication sequence in the present embodiment.
  • the same processes as those already described are denoted by the same reference numerals, and redundant description may be omitted.
  • a participation registration application is activated in response to a user operation or the like (S109).
  • the wireless communication device 105 transmits a participation request message 613A to the access point 102 (S110A).
  • the access point 102 receives the participation request message 613A
  • the access point 102 generates the participation request message 614A by adding the access point information 665 to the participation request message 613A, and transmits the generated participation request message 614A to the server 103 ( S111A).
  • the configuration of the participation request message 614A is the same as the configuration of the participation confirmation message 614 shown in FIG. 15, for example.
  • the server 103 transmits an authentication code request message 615A to the access point 102 (S113). Note that the processing in steps S113 to S117 is the same as the processing described with reference to FIG.
  • the server 103 When the server 103 receives the authentication code information message 616B from the access point 102, the server 103 checks the validity of the authentication code 666 included in the received authentication code information message 616B (S118). If the authentication code 666 is valid, The server 103 registers the wireless communication apparatus 101 having the ID linked to the received authentication code 666 as a terminal having a connection request to the access point 102 (S108A). Next, in the wireless communication apparatus 101, a wireless parameter automatic setting application is activated by a user operation or the like (S101). Note that the processing in steps S101 to S106 is the same as the processing described with reference to FIG.
  • the server 103 checks whether there is a terminal that has a connection request to the access point 102. Specifically, the server 103 determines whether or not the access point indicated by the access point information 665 included in the participation confirmation message 614 and the access point indicated by the access point information 664 included in the connection request message 612 are the same. (S112). When the terminal exists (when the access points indicated by the access point information 665 and 664 are the same), the server 103 confirms the validity of the ID 661 included in the received connection request message 612 (S107).
  • the authentication code 666 included in the message 616B is generated (S119). Note that the subsequent processing (S120 to S133) is the same as the processing described in FIG.
  • the wireless communication device 105 makes a wireless network participation request by registering in advance a wireless communication device that newly joins the wireless network.
  • the wireless parameters can be set quickly.
  • FIGS. 29, 30, and 31 are flowcharts showing the processing of the access point 102 in the present embodiment.
  • the access point 102 waits to receive a participation request message 613A from the wireless communication device 105 (S303A).
  • the access point 102 transmits a participation request message 614A including the access point information 665 indicating the access point 102 to the server 103 (S306A).
  • the access point 102 After transmitting the participation request message 614A, the access point 102 waits to receive the authentication code request message 615A from the server 103 (S307). When the access point 102 receives the authentication code request message 615A (YES in S307), the access point 102 transmits the authentication code request message 615B to the wireless communication apparatus 105 (S310). Note that the processing in steps S310 to S312 is the same as the processing described in FIG.
  • the access point 102 After transmitting the authentication code information message 616B, the access point 102 waits until a rejection notification message is received from the server 103 or a connection request message 611 is received from the wireless communication apparatus 101 (S304 and S301). When the access point 102 receives the rejection notification message (YES in S304), the access point 102 transmits the rejection notification message to the wireless communication device 105 (S305A), and ends this process.
  • connection request message 611 when the access point 102 receives the connection request message 611 from the wireless communication apparatus 101 (YES in S301), the access point information 664 indicating the random value 663 and ID 661 included in the connection request message 611, and the access point 102.
  • a connection request message 612 including the above is transmitted to the server 103 (S302).
  • the subsequent processing (S313 to S325) is the same as the processing described with reference to FIGS. 22 and 23, and the description thereof is omitted.
  • FIG. 32 and 33 are flowcharts showing the processing of the server 103 in this embodiment.
  • the server 103 waits to receive a participation request message 614A from the access point 102 (S404A).
  • the server 103 receives the participation request message 614A from the access point 102 (YES in S404A)
  • the server 103 transmits an authentication code request message 615A to the access point 102 (S406). Note that the processing in steps S406 to S407 is the same as the processing described with reference to FIG.
  • the server 103 When the server 103 receives the authentication code information message 616B (YES in S407), the server 103 checks whether or not the authentication code 666 added to the authentication code information message 616B is a valid authentication code (S408). For example, the server 103 refers to the account management information stored in the storage unit 408, and receives if the authentication code associated with the ID registered in advance as a valid ID matches the received authentication code 666. The authentication code is valid.
  • the server 103 transmits a rejection notification message to the access point 102 (S416), and the process ends.
  • the server 103 registers the ID of the wireless communication device linked to the authentication code 666 (S403A).
  • the server 103 After registering the ID of the wireless communication device, the server 103 waits to receive a connection request message 612 from the access point 102 (S401). When the server 103 receives the connection request message 612 (YES in S401), the access point indicated by the access point information 664 included in the connection request message 612 is indicated by the access point information 665 included in the participation request message 614A. It is confirmed whether it is the same as the access point (S405).
  • the server 103 waits until receiving the connection request message 612 from the access point 102 (S401).
  • the server 103 checks whether or not the ID 661 included in the connection request message 612 is a valid ID (S402). ).
  • the server 103 refers to the account management information stored in the storage unit 408, and determines that the received ID 661 is valid if the ID registered in advance as the valid ID matches the received ID 661.
  • the server 103 transmits a rejection notification message to the access point 102 (S416), and ends this process.
  • the server 103 uses the random value 663 included in the connection request message 612 and the authentication code 666 included in the authentication code information message 616B to use the PIN code. 667 is generated (S409). Note that the subsequent processing (S410 to S415) is the same as the processing described with reference to FIG.
  • FIG. 34 is a flowchart showing processing of wireless communication apparatus 105 in the present embodiment.
  • the wireless communication apparatus 105 transmits a participation request message 613A to the access point 102 (S501A). Note that the subsequent processing (S502 to S507) is the same as the processing described with reference to FIG.
  • wireless communication apparatus 101 transmits a wireless signal after transmitting connection request message 611.
  • the wireless communication device 105 receives a wireless signal transmitted from the wireless communication device 101, the wireless communication device 105 transmits a participation confirmation message 613. Thereby, it is possible to prevent the participation confirmation message 613 from being erroneously transmitted.
  • FIGS. FIG. 4 and FIG. 5 are the same as those in the first embodiment, and a description thereof will be omitted.
  • FIG. 35 is a block diagram illustrating an example of the configuration of the wireless communication apparatus 101 according to the present embodiment.
  • a wireless communication apparatus 101 shown in FIG. 35 includes an output signal strength control unit 209 and a time measuring unit 210 in addition to the configuration shown in FIG.
  • the output signal strength control unit 209 controls the output strength of the radio signal.
  • the timer unit 210 manages timer processing and time.
  • FIG. 36 and 37 are sequence diagrams showing an account authentication sequence in the present embodiment. Note that the processing in steps S101 to S108 is the same as the processing described with reference to FIG.
  • the wireless communication apparatus 101 After transmitting the connection request message 611 to the access point 102, the wireless communication apparatus 101 starts transmitting a wireless signal (beacon) (S141). The wireless communication apparatus 101 gradually increases the transmission strength of the wireless signal until the PIN code generation completion message 618 is received.
  • the wireless communication device 105 receives a wireless signal from the wireless communication device 101 after the participation registration application is activated by a user operation or the like. (S143).
  • the wireless communication device 105 transmits a participation confirmation message 613 to the access point 102 (S110).
  • the subsequent processing (S111 to S133) is the same as the processing described with reference to FIGS. 6 and 7, and description thereof is omitted.
  • the wireless communication apparatus 101 transmits a connection request message 611 to a first wireless access point (for example, the access point 102 or 102A), and then transmits a wireless signal (S142).
  • a first wireless access point for example, the access point 102 or 102A
  • the wireless communication device 105 transmits a participation confirmation message 613 to the second wireless access point (access point 102) (S110).
  • the participation confirmation message is not transmitted until the wireless communication apparatus 105 that has already established a connection with the access point 102 receives a wireless signal transmitted from the wireless communication apparatus 101 that newly participates in the wireless network.
  • the participation confirmation message 613 it is possible to prevent the participation confirmation message 613 from being erroneously transmitted from a user who is away from the wireless communication apparatus 101 that requests new registration.
  • steps S201 and S202 are the same as the processing described with reference to FIG.
  • the wireless communication apparatus 101 After transmitting the connection request message 611, the wireless communication apparatus 101 starts transmitting a wireless signal (beacon) (S210).
  • the wireless communication apparatus 101 determines whether or not the PIN code generation completion message 618 has been received from the access point 102 after starting the transmission of the wireless signal (S203). If the wireless communication apparatus 101 has not received the PIN code generation completion message 618 (NO in S203), the wireless communication apparatus 101 determines whether a protocol failure message has been received from the access point 102 (S204). If the wireless communication apparatus 101 receives a protocol failure message (YES in S204), the wireless communication apparatus 101 ends this process.
  • the wireless communication device 101 determines whether or not the transmission output strength of the current wireless signal is the upper limit value (S211). If the transmission output intensity is the upper limit value (YES in S211), the wireless communication apparatus 101 returns to step S203. If the transmission output intensity is not the upper limit value (NO in S211), the wireless communication apparatus 101 determines whether or not a predetermined time has elapsed since the transmission output intensity of the wireless signal was changed (S212). If the certain time has not elapsed (NO in S212), the wireless communication apparatus 101 returns to step S203. If the predetermined time has elapsed (YES in S212), the wireless communication apparatus 101 increases the transmission output intensity of the wireless signal (S213), and returns to step S203.
  • the wireless communication apparatus 101 when the wireless communication apparatus 101 receives the PIN code generation completion message 618 from the access point 102 (YES in S203), the wireless communication apparatus 101 generates a PIN code using the authentication code 662 and the random value 663 (S205). Note that the processing in steps S206 to S209 is the same as the processing described with reference to FIG.
  • the processing procedure when the access point 102 executes the setting information communication protocol in the present embodiment is the same as that in the first embodiment described with reference to FIGS. 21, 22, and 23, and the description thereof is omitted.
  • the processing procedure of the server 103 that performs authentication is the same as that in the first embodiment described with reference to FIGS. .
  • FIG. 39 is a flowchart showing processing of wireless communication apparatus 105 in the present embodiment. Note that a common encryption key, authentication key, and the like are already set in the wireless communication device 105 and the access point 102. Therefore, the wireless communication apparatus 105 can perform normal data communication using encryption and authentication in the wireless network of the access point 102.
  • the wireless communication device 105 waits until a wireless signal is received from the wireless communication device 101 (S510).
  • the wireless communication apparatus 105 receives a wireless signal from the wireless communication apparatus 101 (YES in S510)
  • the wireless communication apparatus 105 transmits a participation confirmation message 613 to the access point 102 (S501).
  • the subsequent processing (S502 to S507) is the same as the processing described with reference to FIG.
  • server 103 As described above in Embodiments 1 to 3, server 103 according to the present embodiment establishes communication between the first wireless communication device (wireless communication device 101) and the wireless access point (access point 102). For this purpose, the server 103 performs wireless connection authentication, and performs the processing shown in FIG.
  • the first receiving unit included in the server 103 receives first access point information (access point) indicating a first wireless access point (for example, the access point 102 or 102A) from the first wireless communication device (wireless communication device 101).
  • Information 664) is received (S601).
  • the first receiving unit receives the second message (connection request message 612) including the first access point information (access point information 664).
  • the second message (connection request message 612) is a first wireless access point (for example, the access point 102 or the access point 102) according to the first message (connection request message 611) transmitted from the first wireless communication device (wireless communication device 101).
  • 102A is the transmitted message.
  • the second receiving unit included in the server 103 has already established communication with a second wireless access point (access point 102) that is the same as or different from the first wireless access point (access point 102 or 102A).
  • Second access point information (access point information 665) indicating the second wireless access point (access point 102) is received from the wireless communication device (wireless communication device 105) (S602).
  • the second receiving unit receives the fourth message (participation confirmation message 614 or participation request message 614A) including the second access point information.
  • the fourth message (participation confirmation message 614 or participation request message 614A) is sent in accordance with the third message (participation confirmation message 613 or participation request message 613A) transmitted from the second wireless communication apparatus (wireless communication apparatus 105).
  • 2 is a message transmitted by the wireless access point (access point 102).
  • step S602 may be performed after step S601, or as described in the second embodiment, step S601 may be performed after step S602.
  • the determination unit included in the server 103 compares the first wireless access point indicated by the first access point information with the second wireless access point indicated by the second access point information (S603). Then, when the first wireless access point and the second wireless access point are the same wireless access point (YES in S603), the determination unit selects the same wireless access point as the connection destination of the first wireless communication device. A connection destination access point which is a wireless access point is determined (S604).
  • the authentication processing unit included in the server 103 performs processing for performing wireless connection authentication between the connection destination access point and the first wireless communication device (S605).
  • the authentication processing unit performs the processes of steps S406 to S416 shown in FIGS.
  • the first receiving unit and the second receiving unit are realized by, for example, the communication unit 401 and the communication control unit 402 shown in FIG.
  • the determination unit is realized by, for example, the determination unit 407 illustrated in FIG.
  • the authentication processing unit is realized by, for example, the authentication processing unit 405 illustrated in FIG.
  • the server 103 can perform the second wireless communication device.
  • the connection target wireless access point (access point 102) according to the third message transmitted from the (wireless communication device 105)
  • the connection target wireless access point of the first wireless communication device is determined. Can be determined.
  • the user only needs to perform an operation for causing the first wireless communication apparatus to transmit the first message and an operation for causing the second wireless communication apparatus to transmit the third message.
  • the user can perform wireless connection authentication with a simple operation.
  • the server 103 receives a first code (authentication code 666) unique to the first wireless communication device from the second wireless communication device.
  • the server 103 uses the first code to generate a second code (PIN code 667) used for wireless connection authentication between the first wireless communication apparatus and the connection destination access point.
  • the server 103 transmits the second code to the connection destination access point.
  • each of the first message and the second message further includes a third code (random value 663).
  • the server 103 generates the second code using the first code and the third code.
  • the third code is not limited to the random value 663 and may be an arbitrary code. Thereby, it is possible to prevent an unintended device from being erroneously authenticated.
  • an IEEE 802.11 wireless LAN has been described as an example.
  • the present embodiment may be applied to other communication methods such as wireless USB or Bluetooth (registered trademark).
  • the present invention is realized as a wireless communication device, an access point, or a server included in the communication system. May be. Further, the present invention may be realized as a wireless connection authentication method in a communication system, a wireless communication device, an access point, or a server.
  • each component may be configured by dedicated hardware or may be realized by executing a software program suitable for each component.
  • Each component may be realized by a program execution unit such as a CPU or a processor reading and executing a software program recorded on a recording medium such as a hard disk or a semiconductor memory.
  • the software that realizes the server of each of the above embodiments is a program as follows.
  • this program is a program for causing a computer to execute a wireless connection authentication method in a server that performs wireless connection authentication for establishing communication between the first wireless communication device and the wireless access point.
  • the program receives a second message including first access point information indicating the first wireless access point, which is transmitted from the first wireless access point according to the first message transmitted from the first wireless communication device to the computer.
  • the second wireless access point according to a first reception step and a third message transmitted from a second wireless communication device that has already established communication with a second wireless access point that is the same as or different from the first wireless access point.
  • the same wireless access point is connected to the wireless access point to which the first wireless communication device is connected.
  • a determination step of determining as a destination access point and an authentication processing step of performing processing for performing wireless connection authentication between the connection destination access point and the first wireless communication device are executed.
  • the present invention may be the above program or a non-transitory computer-readable recording medium on which the above program is recorded.
  • the program can be distributed via a transmission medium such as the Internet.
  • division of functional blocks in the block diagram is an example, and a plurality of functional blocks can be realized as one functional block, a single functional block can be divided into a plurality of functions, or some functions can be transferred to other functional blocks. May be.
  • functions of a plurality of functional blocks having similar functions may be processed in parallel or time-division by a single hardware or software.
  • the order in which the steps included in the above processes are executed is for illustrating the present invention specifically, and may be an order other than the above as long as the same result can be obtained. . Also, some of the above steps may be executed simultaneously (in parallel) with other steps.
  • the communication system according to one or more aspects has been described based on the embodiment.
  • the present invention is not limited to this embodiment. Unless it deviates from the gist of the present invention, various modifications conceived by those skilled in the art have been made in this embodiment, and forms constructed by combining components in different embodiments are also within the scope of one or more aspects. May be included.
  • the present invention is useful as a wireless LAN simple connection method and the like.
  • the present invention can also be applied to uses such as connection of a public wireless LAN.

Landscapes

  • Engineering & Computer Science (AREA)
  • Computer Security & Cryptography (AREA)
  • Computer Networks & Wireless Communication (AREA)
  • Signal Processing (AREA)
  • Mobile Radio Communication Systems (AREA)

Abstract

 無線接続認証方法は、第1無線通信装置(101)から送信されたメッセージ(611)に従い第1アクセスポイント(102又は102A)が送信した、第1情報(664)を受信するステップ(S601)と、第2アクセスポイント(102)と既に通信が確立している第2無線通信装置(105)から送信されたメッセージ(613)に従い、第2アクセスポイント(102)が送信した第2情報(665)を受信するステップ(S602)と、第1情報(664)で示される第1アクセスポイント(102又は102A)と、第2情報(665)で示される第2アクセスポイント(102)とが同一のアクセスポイントである場合、当該同一のアクセスポイントを、第1無線通信装置(101)の接続先のアクセスポイントに決定するステップ(S604)とを含む。

Description

無線接続認証方法及びサーバ
 本発明は、無線接続認証方法及びサーバに関する。
 無線LANを使用する際には、無線通信装置に対してネットワーク識別子(ESSID)、周波数チャネル、暗号方式、暗号鍵、認証方式、及び認証鍵等の無線パラメータをユーザが設定する必要がある。これらの設定作業は煩雑なため、端末間で自動的に無線パラメータを設定する方法が存在する(例えば、特許文献1を参照)。
特開2009-253380号公報
 このような無線接続認証方法では、ユーザがより簡単な操作で無線接続認証を行えることが望まれている。
 そこで、本発明は、ユーザが簡単な操作で無線接続認証を行える無線接続認証方法を提供することを目的とする。
 本発明の一態様に係る無線接続認証方法は、第1無線通信装置と無線アクセスポイントとの通信を確立するための無線接続認証を行うサーバにおける無線接続認証方法であって、前記第1無線通信装置から送信された第1メッセージに従い第1無線アクセスポイントが送信した、前記第1無線アクセスポイントを示す第1アクセスポイント情報を含む第2メッセージを受信する第1受信ステップと、前記第1無線アクセスポイントと同一又は異なる第2無線アクセスポイントと既に通信が確立している第2無線通信装置から送信された第3メッセージに従い、前記第2無線アクセスポイントが送信した、前記第2無線アクセスポイントを示す第2アクセスポイント情報を含む第4メッセージを受信する第2受信ステップと、前記第1アクセスポイント情報で示される前記第1無線アクセスポイントと、前記第2アクセスポイント情報で示される前記第2無線アクセスポイントとを比較し、前記第1無線アクセスポイントと前記第2無線アクセスポイントとが同一の無線アクセスポイントである場合、当該同一の無線アクセスポイントを、前記第1無線通信装置の接続先の無線アクセスポイントである接続先アクセスポイントに決定する決定ステップと、前記接続先アクセスポイントと前記第1無線通信装置との無線接続認証を行うための処理を行う認証処理ステップとを含む。
 また、本発明の一態様に係る無線接続認証方法は、第1無線通信装置と無線アクセスポイントとの無線接続認証を行う無線接続認証方法であって、前記第1無線通信装置が、第1メッセージを第1無線アクセスポイントに送信する第1メッセージ送信ステップと、前記第1メッセージを受信した前記第1無線アクセスポイントが、前記第1無線アクセスポイントを示す第1アクセスポイント情報を含む第2メッセージをサーバに送信する第2メッセージ送信ステップと、前記第1無線アクセスポイントと同一又は異なる第2無線アクセスポイントと無線接続認証が既に完了している第2無線通信装置が、第3メッセージを前記第2無線アクセスポイントに送信する第3メッセージ送信ステップと、前記第3メッセージを受信した前記第2無線アクセスポイントが、前記第2無線アクセスポイントを示す第2アクセスポイント情報を含む第4メッセージを前記サーバに送信する第4メッセージ送信ステップと、前記サーバが、前記第1アクセスポイント情報で示される前記第1無線アクセスポイントと、前記第2アクセスポイント情報で示される前記第2無線アクセスポイントとを比較し、前記第1無線アクセスポイントと前記第2無線アクセスポイントとが同一の無線アクセスポイントである場合、当該同一の無線アクセスポイントを、前記第1無線通信装置の接続先の無線アクセスポイントである接続先アクセスポイントに決定する決定ステップと、前記接続先アクセスポイントと前記第1無線通信装置とが無線接続認証を行う認証ステップとを含む。
 なお、これらの全般的または具体的な態様は、システム、方法、集積回路、コンピュータプログラムまたはコンピュータ読み取り可能なCD-ROMなどの記録媒体で実現されてもよく、システム、方法、集積回路、コンピュータプログラム及び記録媒体の任意な組み合わせで実現されてもよい。
 本発明は、ユーザが簡単な操作で無線接続認証を行える無線接続認証方法を提供できる。
図1は、実施の形態1における通信システムの構成例を示す図である。 図2は、実施の形態1における無線通信装置の構成例を示すブロック図である。 図3は、実施の形態1におけるアクセスポイントの構成例を示すブロック図である。 図4は、実施の形態1におけるサーバの構成例を示すブロック図である。 図5は、実施の形態1における既にアクセスポイントと通信を確立している無線通信装置の構成例を示すブロック図である。 図6は、実施の形態1におけるアカウント認証処理のシーケンス図である。 図7は、実施の形態1におけるアカウント認証処理のシーケンス図である。 図8は、実施の形態1におけるネットワーク接続要求のための操作例を説明するための図である。 図9は、実施の形態1における無線通信装置に格納される情報の一例を示す図である。 図10は、実施の形態1における接続要求メッセージの構成例を示す図である。 図11は、実施の形態1における接続要求メッセージの構成例を示す図である。 図12は、実施の形態1における接続要求メッセージが送信される様子を示す図である。 図13は、実施の形態1におけるサーバに記憶される情報の一例を示す図である。 図14は、実施の形態1におけるネットワーク参加確認要求のための操作例を説明するための図である。 図15は、実施の形態1における参加確認メッセージの構成例を示す図である。 図16は、実施の形態1における認証コードの入力操作の一例を示す図である。 図17は、実施の形態1における認証コード情報メッセージの構成例を示す図である。 図18は、実施の形態1におけるPINコード情報メッセージの構成例を示す図である。 図19は、実施の形態1における無線接続認証が完了した際の表示例を示す図である。 図20は、実施の形態1における無線通信装置の処理を示すフローチャートである。 図21は、実施の形態1におけるアクセスポイントの処理を示すフローチャートである。 図22は、実施の形態1におけるアクセスポイントの処理を示すフローチャートである。 図23は、実施の形態1におけるアクセスポイントの処理を示すフローチャートである。 図24は、実施の形態1におけるサーバの処理を示すフローチャートである。 図25は、実施の形態1におけるサーバの処理を示すフローチャートである。 図26は、実施の形態1における既にアクセスポイントと通信を確立している無線通信装置の処理を示すフローチャートである。 図27は、実施の形態2におけるアカウント認証処理のシーケンス図である。 図28は、実施の形態2におけるアカウント認証処理のシーケンス図である。 図29は、実施の形態2におけるアクセスポイントの処理を示すフローチャートである。 図30は、実施の形態2におけるアクセスポイントの処理を示すフローチャートである。 図31は、実施の形態2におけるアクセスポイントの処理を示すフローチャートである。 図32は、実施の形態2におけるサーバの処理を示すフローチャートである。 図33は、実施の形態2におけるサーバの処理を示すフローチャートである。 図34は、実施の形態2における既にアクセスポイントと通信を確立している無線通信装置の処理を示すフローチャートである。 図35は、実施の形態3における無線通信装置の構成例を示すブロック図である。 図36は、実施の形態3におけるアカウント認証処理のシーケンス図である。 図37は、実施の形態3におけるアカウント認証処理のシーケンス図である。 図38は、実施の形態3における無線通信装置の処理を示すフローチャートである。 図39は、実施の形態3における既にアクセスポイントとの通信を確立している無線通信装置の処理を示すフローチャートである。 図40は、実施の形態におけるサーバの処理を示すフローチャートである。
 (本発明の基礎となった知見)
 本発明者は、「背景技術」の欄において記載した、無線認証接続方法に関し、以下の問題が生じることを見出した。
 自動的に無線パラメータを設定する方法として、Wi-Fi Allianceという団体によって定められたWi-Fi Protected Setup(WPS)という無線パラメータ自動設定方法が存在する。
 このWPSでは、無線パラメータの設定処理用の特別なプロトコルとして、Registration(登録)プロトコルを用いてRegistrar(レジストラ)からEnrollee(エンローリー)へ無線パラメータが提供される。なお、レジストラとは、無線パラメータを管理し、エンローリーへ無線パラメータを提供する装置である。また、エンローリーとは、レジストラから提供された無線パラメータを受理する装置である。
 登録プロトコルにおけるレジストラとエンローリー間の通信は、EAP(Extensible Auth entication Protocol)パケットを用いて行われる。EAPパケットとは、レジストラとエンローリー間において、暗号化及び認証を行うことなく通信できるパケットである。
 例として、レジストラとして動作するアクセスポイントから、エンローリーとして動作する無線通信装置に対して無線パラメータを提供する場合を説明する。まず、無線通信装置は、アクセスポイントが形成するネットワークを探索し、当該ネットワークに一時的に参加する。この時点では、アクセスポイントと無線通信装置におけるESSIDと周波数チャネルは一致しているが、暗号鍵及び認証鍵等は一致していないため、暗号及び認証を用いた通常のデータ通信を行うことはできない。
 アクセスポイントと無線通信装置は、登録プロトコルによりEAPパケットを用いたメッセージの送受信を行う。これにより、アクセスポイントから無線通信装置に対して無線パラメータが提供される。無線通信装置は、提供された無線パラメータを新たに設定することにより、アクセスポイントとの間で暗号及び認証を用いたデータ通信を行うことが可能になる。
 WPSが提供する設定方式にはプッシュボタン方式と、PIN(Personal Identification Number)コード方式がある。プッシュボタン方式では無線パラメータの自動設定を行うことができるが、設定中にネットワーク内に存在する他のアクセスポイントがプッシュボタン方式による無線パラメータ設定を行っている場合、無線通信装置が他のアクセスポイントと意図せず接続される可能性がある。
 PINコード方式では、無線通信装置が他のアクセスポイントと意図せず接続されることはないが、ユーザがアクセスポイントを選択し、PINコードを設定する必要があり、ユーザに手間がかかるという課題がある。
 そのため、アカウント管理サーバを用いてユーザの認証を行うことでユーザの操作性を向上させる手法が提案されている(例えば、特許文献1参照)。特許文献1では、ユーザが所望のアクセスポイントに対して接続要求を送信し、接続要求を受信したアクセスポイントは接続要求を送信したユーザのユーザアカウントをアカウント管理サーバに送信する。アカウント管理サーバは、ユーザアカウントを管理するとともに、ユーザを認証してPINコードを生成し、アクセスポイントにPINコードを付与することで無線通信装置に通信許可を与える。このように、アカウント管理サーバがPINコードを生成することで、ユーザはPINコードを設定することなく、無線接続設定を行うことができる。
 しかしながら、上記手法では、ユーザはネットワーク内に存在するアクセスポイントの中から所望のアクセスポイントを選択する必要があるため、ユーザの負担となっていた。
 以下の実施の形態では、既にアクセスポイントと接続が確立されている無線通信装置を用いて新たにアクセスポイントと接続する無線通信装置の認証を行う。これにより、ユーザがアクセスポイントを選択することなく、無線通信装置とアクセスポイントの無線パラメータの設定できる。よって、ユーザの操作性を向上させることができる。
 本発明の一態様に係る無線接続認証方法は、第1無線通信装置と無線アクセスポイントとの通信を確立するための無線接続認証を行うサーバにおける無線接続認証方法であって、前記第1無線通信装置から送信された第1メッセージに従い第1無線アクセスポイントが送信した、前記第1無線アクセスポイントを示す第1アクセスポイント情報を含む第2メッセージを受信する第1受信ステップと、前記第1無線アクセスポイントと同一又は異なる第2無線アクセスポイントと既に通信が確立している第2無線通信装置から送信された第3メッセージに従い、前記第2無線アクセスポイントが送信した、前記第2無線アクセスポイントを示す第2アクセスポイント情報を含む第4メッセージを受信する第2受信ステップと、前記第1アクセスポイント情報で示される前記第1無線アクセスポイントと、前記第2アクセスポイント情報で示される前記第2無線アクセスポイントとを比較し、前記第1無線アクセスポイントと前記第2無線アクセスポイントとが同一の無線アクセスポイントである場合、当該同一の無線アクセスポイントを、前記第1無線通信装置の接続先の無線アクセスポイントである接続先アクセスポイントに決定する決定ステップと、前記接続先アクセスポイントと前記第1無線通信装置との無線接続認証を行うための処理を行う認証処理ステップとを含む。
 これによれば、ユーザは、第1無線通信装置に第1メッセージを送信させる操作と、第2無線通信装置に第3メッセージを送信させる操作とのみを行えばよい。このように、ユーザは、簡単な操作で無線接続認証を行うことができる。
 例えば、前記無線接続認証方法は、さらに、前記第2無線通信装置から前記第1無線通信装置に固有の第1コードを受信する第3受信ステップを含み、前記認証処理ステップは、前記第1コードを用いて、前記第1無線通信装置と前記接続先アクセスポイントとの無線接続認証に用いられる第2コードを生成する第2コード生成ステップと、前記第2コードを前記接続先アクセスポイントに送信する送信ステップとを含んでもよい。
 これによれば、意図しない機器が誤って認証されることを防止できる。
 例えば、前記第1メッセージ及び前記第2メッセージの各々は、さらに、第3コードを含み、前記第2コード生成ステップでは、前記第1コード及び前記第3コードを用いて前記第2コードを生成してもよい。
 これによれば、意図しない機器が誤って認証されることを防止できる。
 また、本発明の一態様に係る無線接続認証方法は、第1無線通信装置と無線アクセスポイントとの無線接続認証を行う無線接続認証方法であって、前記第1無線通信装置が、第1メッセージを第1無線アクセスポイントに送信する第1メッセージ送信ステップと、前記第1メッセージを受信した前記第1無線アクセスポイントが、前記第1無線アクセスポイントを示す第1アクセスポイント情報を含む第2メッセージをサーバに送信する第2メッセージ送信ステップと、前記第1無線アクセスポイントと同一又は異なる第2無線アクセスポイントと無線接続認証が既に完了している第2無線通信装置が、第3メッセージを前記第2無線アクセスポイントに送信する第3メッセージ送信ステップと、前記第3メッセージを受信した前記第2無線アクセスポイントが、前記第2無線アクセスポイントを示す第2アクセスポイント情報を含む第4メッセージを前記サーバに送信する第4メッセージ送信ステップと、前記サーバが、前記第1アクセスポイント情報で示される前記第1無線アクセスポイントと、前記第2アクセスポイント情報で示される前記第2無線アクセスポイントとを比較し、前記第1無線アクセスポイントと前記第2無線アクセスポイントとが同一の無線アクセスポイントである場合、当該同一の無線アクセスポイントを、前記第1無線通信装置の接続先の無線アクセスポイントである接続先アクセスポイントに決定する決定ステップと、前記接続先アクセスポイントと前記第1無線通信装置とが無線接続認証を行う認証ステップとを含む。
 これによれば、ユーザは、第1無線通信装置に第1メッセージを送信させる操作と、第2無線通信装置に第3メッセージを送信させる操作とのみを行えばよい。このように、ユーザは、簡単な操作で無線接続認証を行うことができる。
 例えば、前記無線接続認証方法は、さらに、ユーザ操作に応じて、前記第2無線通信装置が前記第1無線通信装置に固有の第1コードを取得する取得ステップと、前記第2無線通信装置が、前記第1コードを前記サーバに送信する第1コード送信ステップと、前記サーバが、前記第1コードを用いて、前記第1無線通信装置と前記接続先アクセスポイントとの無線接続認証に用いられる第2コードを生成する第2コード生成ステップと、前記サーバが、前記第2コードを前記接続先アクセスポイントに送信する送信ステップと、前記第1無線通信装置が、前記第1コードと同一の第3コードを用いて第4コードを生成する第4コード生成ステップとを含み、前記認証ステップでは、前記第1無線通信装置及び前記接続先アクセスポイントが、前記第2コードと前記第4コードとが同一であるか否かに応じて、前記第1無線通信装置及び前記接続先アクセスポイントとの無線接続認証を行ってもよい。
 これによれば、意図しない機器が誤って認証されることを防止できる。
 例えば、前記無線接続認証方法は、さらに、前記第1無線通信装置が第5コードを生成する生成ステップを含み、前記第1メッセージ及び前記第2メッセージの各々は、さらに、前記第5コードを含み、前記第2コード生成ステップでは、前記第1コード及び前記第5コードを用いて前記第2コードを生成し、前記第4コード生成ステップでは、前記第3コード及び前記第5コードを用いて前記第4コードを生成してもよい。
 これによれば、意図しない機器が誤って認証されることを防止できる。
 例えば、前記第3メッセージ送信ステップは、前記第1メッセージ送信ステップの後に行われてもよい。
 例えば、前記無線接続認証方法は、さらに、前記第1メッセージ送信ステップの後に、前記第1無線通信装置が、無線信号を送信する無線信号送信ステップを含み、前記第3メッセージ送信ステップでは、前記第2無線通信装置が前記無線信号を受信した場合に、前記第2無線通信装置が、前記第3メッセージを前記第2無線アクセスポイントに送信してもよい。
 これによれば、第3メッセージが誤って送信されることを防止できる。
 例えば、前記第1メッセージ送信ステップは、前記第3メッセージ送信ステップの後に行われてもよい。
 また、本発明の一態様に係るサーバは、第1無線通信装置と無線アクセスポイントとの通信を確立するための無線接続認証を行うサーバであって、前記第1無線通信装置から送信された第1メッセージに従い第1無線アクセスポイントが送信した、前記第1無線アクセスポイントを示す第1アクセスポイント情報を含む第2メッセージを受信する第1受信部と、前記第1無線アクセスポイントと同一又は異なる第2無線アクセスポイントと既に通信が確立している第2無線通信装置から送信された第3メッセージに従い、前記第2無線アクセスポイントが送信した、前記第2無線アクセスポイントを示す第2アクセスポイント情報を含む第4メッセージを受信する第2受信部と、前記第1アクセスポイント情報で示される前記第1無線アクセスポイントと、前記第2アクセスポイント情報で示される前記第2無線アクセスポイントとを比較し、前記第1無線アクセスポイントと前記第2無線アクセスポイントとが同一の無線アクセスポイントである場合、当該同一の無線アクセスポイントを、前記第1無線通信装置の接続先の無線アクセスポイントである接続先アクセスポイントに決定する決定部と、前記接続先アクセスポイントと前記第1無線通信装置との無線接続認証を行うための処理を行う認証処理部とを備える。
 これによれば、ユーザは、第1無線通信装置に第1メッセージを送信させる操作と、第2無線通信装置に第3メッセージを送信させる操作とのみを行えばよい。このように、ユーザは、簡単な操作で無線接続認証を行うことができる。
 なお、これらの全般的または具体的な態様は、システム、方法、集積回路、コンピュータプログラムまたはコンピュータ読み取り可能なCD-ROMなどの記録媒体で実現されてもよく、システム、方法、集積回路、コンピュータプログラム及び記録媒体の任意な組み合わせで実現されてもよい。
 以下、本発明の実施の形態について、図面を参照しながら説明する。
 なお、以下で説明する実施の形態は、いずれも本発明の一具体例を示すものである。以下の実施の形態で示される数値、形状、材料、構成要素、構成要素の配置位置及び接続形態、ステップ、ステップの順序などは、一例であり、本発明を限定する主旨ではない。また、以下の実施の形態における構成要素のうち、最上位概念を示す独立請求項に記載されていない構成要素については、任意の構成要素として説明される。
 (実施の形態1)
 図1は、本実施の形態における代表的な通信システム100の構成の一例を示す図である。この通信システム100は、無線通信装置101及び105と、アクセスポイント102と、サーバ103と、インターネット104とを含む。
 無線通信装置101は、無線LANの通信機能とWPS機能とを有する通信機器であり、例えば、パーソナルコンピュータ、又は無線通信機能を有する家電機器である。アクセスポイント102は、無線LAN及びWPS機能を有する。サーバ103は、無線通信装置のアカウント(ID及び認証コード等)を管理する機能と、無線通信装置を認証して当該無線通信装置に通信許可を与える機能とを有する。インターネット104は、世界中のコンピュータと接続可能な通信ネットワークである。無線通信装置105は、有線LAN、又は無線LANによって既にアクセスポイント102との接続を確立している通信機器であり、例えば、パーソナルコンピュータ、携帯電話、スマートフォン、又はタブレット端末である。以下では、無線通信装置105が無線LANによってアクセスポイント102と接続する例を説明する。
 アクセスポイント102とサーバ103は、インターネット104を介して接続されている。無線通信装置101と無線通信装置105は、アクセスポイント102が構築するインフラストラクチャモードの無線ネットワークに接続されている。無線通信装置105は、既にアクセスポイント102と接続が確立しており、暗号を用いてインターネット104への接続が許可されている。
 無線通信装置101とアクセスポイント102はそれぞれPINコードを設定する。そして、無線通信装置101が無線パラメータ自動設定アプリケーションを開始する。そして、設定情報通知プロトコルにより、無線通信装置101とアクセスポイント102との間で互いに保持するPINコードの一致が確認される。これにより、無線通信装置101は無線パラメータを取得できる。すなわち、PINコードは、無線パラメータの設定処理に用いられるコード情報、又は、無線パラメータの設定処理において無線パラメータを提供してよいか否かの判定に用いられるコード情報である。
 ここで、設定情報通知プロトコルでは、各種メッセージの送受信にEAPパケットが用いられる。そのため、無線通信装置101とアクセスポイント102とは、使用するESSID及び周波数チャネルが互いに一致すれば、無線LANの暗号及び認証無しで設定情報通知プロトコルによる各種メッセージの送受信を行うことができる。したがって、認証が成功するまでは無線通信装置101はアクセスポイント102のみと通信可能である。また、無線通信装置101とサーバ103との通信は、アクセスポイント102がメッセージを転送することで行われる。無線通信装置101はサーバ103との認証が成功した場合にのみインターネット104に接続できる。
 図1に示す無線通信装置101の構成を、図2を参照して説明する。図2は、本実施の形態における無線通信装置101の構成の一例を示すブロック図である。図2に示す無線通信装置101は、通信部201と、通信制御部202と、装置制御部203と、インターフェース処理部204と、無線パラメータ設定処理部205と、符号演算部206と、判断部207と、記憶部208とを備える。
 通信部201は無線通信を行う。通信制御部202は通信部201の制御を行う。装置制御部203は無線通信装置101全体の動作を制御する。インターフェース処理部204は各種インターフェースの制御を行う。無線パラメータ設定処理部205は設定情報通知プロトコルによる無線パラメータ設定処理を行う。符号演算部206は各種信号及びハッシュ値などの演算を行う。判断部207は各種処理の判断を行う。記憶部208は無線パラメータ、アカウント情報、ID、及び認証コード等を記憶する。
 図1に示すアクセスポイント102の構成を、図3を参照して説明する。図3は本実施の形態におけるアクセスポイント102の構成の一例を示すブロック図である。図3に示すアクセスポイント102は、通信部301と、通信制御部302と、装置制御部303と、インターフェース処理部304と、無線パラメータ設定処理部305と、判断部306と、記憶部307とを備える。
 通信部301は無線通信を行う。通信制御部302は通信部301の制御を行う。装置制御部303は装置(アクセスポイント102)全体の動作を制御する。インターフェース処理部304は各種インターフェースの制御を行う。無線パラメータ設定処理部305は設定情報通知プロトコルによる無線パラメータ設定処理を行う。判断部306は各種処理の判断を行う。記憶部307は無線パラメータ、アカウント情報、及びサーバのIP(Internet Protocol)アドレス等を記憶する。
 図1に示すサーバ103の構成を、図4を参照して説明する。図4は本実施の形態におけるサーバ103の構成の一例を示すブロック図である。図4に示すサーバ103は、通信部401と、通信制御部402と、装置制御部403と、インターフェース処理部404と、認証処理部405と、符号演算部406と、判断部407と、記憶部408とを備える。
 通信部401は通信を行う。通信制御部402は通信部401の制御を行う。装置制御部403は装置(サーバ103)全体の動作を制御する。インターフェース処理部404は各種インターフェースの制御を行う。認証処理部405は各種認証処理を行う。符号演算部406は各種信号及びハッシュ値などの演算を行う。判断部407は各種処理の判断を行う。記憶部408は無線パラメータ、アカウント情報、及び認証コード等を記憶する。
 図1に示す既にアクセスポイント102との接続を確立している無線通信装置105の構成を、図5を参照して説明する。図5は本実施の形態における既にアクセスポイント102との接続を確立している無線通信装置105の構成の一例を示すブロック図である。図2に示す無線通信装置105は、通信部501と、通信制御部502と、装置制御部503と、インターフェース処理部504と、無線パラメータ設定処理部505と、判断部506と、記憶部507と、表示部508とを備える。
 通信部501は無線通信を行う。通信制御部502は通信部501の制御を行う。装置制御部503は無線通信装置105全体の動作を制御する。インターフェース処理部504は各種インターフェースの制御を行う。無線パラメータ設定処理部505は設定情報通知プロトコルによる無線パラメータ設定処理を行う。判断部506は各種処理の判断を行う。記憶部507は無線パラメータ及びアカウント情報等を記憶する。表示部508は各種表示を行う。
 次に、無線通信装置101、アクセスポイント102、サーバ103、及び無線通信装置105の間で行われるアカウント認証シーケンスを、図6及び図7を用いて説明する。
 図6及び図7は、本実施の形態におけるアカウント認証シーケンスを示すシーケンス図である。
 まず、無線通信装置101において、ユーザの操作等によって無線パラメータ自動設定アプリケーションが起動される(S101)。図8は、ユーザの操作例を示す図である。例えば、ユーザは、無線通信装置101(例えば冷蔵庫)に設けられている、ネットワーク接続を行うための操作ボタン651を押す。これにより、無線パラメータ自動設定アプリケーションが起動される。
 上記操作が行われると、無線通信装置101は周辺の無線ネットワークを探索する(S102)。次に、無線通信装置101は、探索された複数の無線ネットワークを順次選択し、選択した無線ネットワークに参加する。この例では、アクセスポイント102の無線ネットワークが選択され、無線通信装置101はアクセスポイント102の無線ネットワークに参加する(S103)。しかし、この時点では、無線通信装置101とアクセスポイント102には共通の暗号鍵及び認証鍵等が設定されていない。そのため、無線通信装置101はアクセスポイント102の無線ネットワークにおいて特定の信号(報知信号及びEAPパケット等)のみでしかアクセスポイント102と通信できない状態であり、暗号及び認証を用いた通常のデータ通信を行うことはできない。ここでは、無線通信装置101とアクセスポイント102の間においてEAPパケットを用いて各種メッセージの送受信が行われる。
 次に、無線通信装置101はランダム値を生成する(S104)。次に、無線通信装置101は、ランダム値とIDとを含む接続要求メッセージ611をアクセスポイント102に送信する(S105)。
 図9は、無線通信装置101が備える記憶部208に記憶されている情報の一例を示す図である。図9に示すように、記憶部208は、ID661と、認証コード662とを記憶している。
 ID661は、無線通信装置101を識別するための識別子であり、例えば、無線通信装置101の型番、製造番号、又はこれらの組合せである。なお、ID661は任意の数字又は文字の組合せであってもよい。
 認証コード662は、無線通信装置101を識別するための識別子であり、例えば、無線通信装置101の型番、製造番号、又はこれらの組合せである。なお、認証コード662は任意の数字又は文字の組合せであってもよい。また、ここでは、ID661と認証コード662とを個別に記載しているが、ID661及び認証コード662の一方のみが用いられてもよい。言い換えると、ID661と認証コード662は同一のコード(識別子)であってもよい。
 図10は、接続要求メッセージ611の構成例を示す図である。接続要求メッセージ611は、無線通信装置101がネットワークへの接続をサーバ103に要求するためのメッセージである。言い換えると、接続要求メッセージ611は、無線通信装置101がアクセスポイント102への接続をサーバ103に要求するためのメッセージである。この接続要求メッセージ611は、記憶部208に記憶されているID661と、ステップS104で生成されたランダム値663とを含む。
 なお、接続要求メッセージ611は、必要に応じて上記以外の情報(例えば、当該メッセージの種別を示す情報、並びにメッセージの送信元及び送信先を示す情報等)を含むが、これらの情報は図10には図示していない。また、これらの情報が含まれる点は、後述する各種メッセージにおいても同様である。
 アクセスポイント102は、接続要求メッセージ611を受信した場合、受信した接続要求メッセージ611にアクセスポイント情報664を付加することで接続要求メッセージ612を生成し、生成した接続要求メッセージ612をサーバ103へ送信する(S106)。
 図11は、接続要求メッセージ612の構成例を示す図である。図11に示すように、接続要求メッセージ612は、接続要求メッセージ611に含まれていたID661及びランダム値663と、アクセスポイント情報664とを含む。アクセスポイント情報664は、接続要求メッセージ612の送信元のアクセスポイントを示す情報である。よって、この例では、アクセスポイント情報664は、アクセスポイント102を示す。
 なお、ここでは、アクセスポイント102が、接続要求メッセージ611にアクセスポイント情報664を付加する例を述べたが、無線通信装置101がアクセスポイント情報664を含む接続要求メッセージ611を生成してもよい。この場合、アクセスポイント情報664は、接続要求メッセージ611の送信先のアクセスポイントを示す。
 サーバ103は、接続要求メッセージ612を受信した場合、受信した接続要求メッセージ612に含まれるID661の有効性を確認し(S107)、ID661が有効である場合は、受信したID661を持つ無線通信装置101をアクセスポイント102への接続要求がある端末として登録する(S108)。
 ここで、ステップS102において、複数の無線ネットワークが探索された場合には、複数のアクセスポイントの各々に対してステップS103及びS105を行う。これにより、サーバ103は、異なるアクセスポイントを経由した複数の接続要求メッセージ612を受信する。例えば、図12に示すように、無線通信装置101に近くにアクセスポイント102(AP1)と、アクセスポイント102A(AP2)とが存在する場合、アクセスポイント102を経由した接続要求メッセージ612と、アクセスポイント102Aを経由した接続要求メッセージ612とが、サーバ103で受信される。
 この場合、図13に示すように、2つの接続要求メッセージ612に対応する情報(ID671、ランダム値672及びアクセスポイント情報673)がサーバ103に登録される。ここで、2つの接続要求メッセージ612は、当該メッセージを経由したアクセスポイントが異なるため、アクセスポイント情報673で示されるアクセスポイントが異なる。なお、図13では、2つの接続要求メッセージ612のID671及びランダム値672が同一であるが、これらの少なくとも一方が異なってもよい。
 次に、既にアクセスポイント102と接続が確立している無線通信装置105において、ユーザの操作等によって参加登録アプリケーションが起動される(S109)。図14は、ユーザの操作例を示す図である。例えば、ユーザは、無線通信装置105(例えばスマートフォン)において、ネットワーク参加確認を行うための操作メニュー652を選択する。これにより、参加登録アプリケーションが起動される。
 次に、無線通信装置105は参加確認メッセージ613をアクセスポイント102に送信する(S110)。アクセスポイント102は参加確認メッセージ613を受信した場合、参加確認メッセージ613にアクセスポイント情報665を付加することで参加確認メッセージ614を生成し、生成された参加確認メッセージ614をサーバ103に送信する(S111)。
 図15は、参加確認メッセージ614の構成例を示す図である。図15に示すように、参加確認メッセージ614は、アクセスポイント情報665を含む。アクセスポイント情報665は、参加確認メッセージ614の送信元のアクセスポイントを示す情報である。よって、この例では、アクセスポイント情報665は、アクセスポイント102を示す。
 なお、ここでは、アクセスポイント102が、参加確認メッセージ614にアクセスポイント情報665を付加する例を述べたが、無線通信装置105がアクセスポイント情報665を含む参加確認メッセージ613を生成してもよい。この場合、アクセスポイント情報665は、参加確認メッセージ613の送信先のアクセスポイントを示す。
 また、いずれの場合でも、アクセスポイント情報665は、無線通信装置105が既に通信を確立しているアクセスポイント102を示す。また、アクセスポイント情報665は、無線通信装置101の接続先のアクセスポイント102を示す。
 サーバ103は、参加確認メッセージ614を受信した場合、アクセスポイント102への接続要求がある端末が存在するかを確認する。具体的には、サーバ103は、参加確認メッセージ614に含まれるアクセスポイント情報665で示されるアクセスポイントと、同一のアクセスポイントを示すアクセスポイント情報673が存在するかを確認する(S112)。
 例えば、図13に示すように、アクセスポイント情報673としてAP1(アクセスポイント102)とAP2(アクセスポイント102A)とが登録されている場合、サーバ103は、アクセスポイント情報665で示されるAP1(アクセスポイント102)を、無線通信装置101の接続先に決定する。
 次に、サーバ103は、接続先に決定されたアクセスポイント102に認証コード要求メッセージ615Aを送信する(S113)。アクセスポイント102は、認証コード要求メッセージ615Aを受信した場合、無線通信装置105に認証コード要求メッセージ615Bを送信する(S114)。
 無線通信装置105は、認証コード要求メッセージ615Bを受信した場合、ユーザの操作等に応じて認証コードを生成する(S115)。例えば、図16に示すように、ユーザは、入力メニュー653に認証コードを入力する。ここで、入力される認証コードは、無線通信装置101に固有の数字又は文字列であり、無線通信装置101の記憶部208に記憶されている認証コード662と同一である。例えば、ユーザは、無線通信装置101(例えば、家電機器)の筐体、又は取扱説明書等に記載されている認証コードを確認し、当該認証コードを入力メニュー653に入力する。
 なお、ユーザは、無線通信装置101の筐体、又は取扱説明書等に記載されているバーコード又は二次元バーコード等を、無線通信装置105(例えばスマートフォン)で撮影してもよい。これにより、無線通信装置105は、認証コードを取得できる。
 次に、無線通信装置105は、アクセスポイント102に認証コード情報メッセージ616Aを送信する(S116)。図17は、認証コード情報メッセージ616Aの構成例を示す図である。図17に示すように、認証コード情報メッセージ616Aは、ステップS115で生成された認証コード666を含む。
 アクセスポイント102は、認証コード情報メッセージ616Aを受信した場合、認証コード情報メッセージ616Aに含まれる認証コード666を含む認証コード情報メッセージ616Bをサーバ103に送信する(S117)。例えば、認証コード情報メッセージ616Bの構成例は、図17に示す認証コード情報メッセージ616Aの構成例と同じである。
 サーバ103は、認証コード情報メッセージ616Bを受信した場合、受信した認証コード情報メッセージ616Bに含まれる認証コード666の有効性を確認する(S118)。認証コード666が有効である場合は、サーバ103は、アクセスポイント102への接続要求がある端末である無線通信装置101の無線パラメータ設定のためのPINコードを、接続要求メッセージ612に含まれていたランダム値663と、認証コード情報メッセージ616Bに含まれていた認証コード666を用いて生成する(S119)。
 次に、サーバ103は、図18に示すように、生成したPINコード667を含むPINコード情報メッセージ617をアクセスポイント102に送信する(S120)。アクセスポイント102は、PINコード情報メッセージ617を受信した場合、無線パラメータ自動設定アプリケーションを起動し、付加されているPINコード667を無線パラメータ自動設定アプリケーションに設定する(S121)。アクセスポイント102は、PINコードを設定した後、PINコード生成完了メッセージを無線通信装置101に送信する(S122)。
 無線通信装置101は、PINコード生成完了メッセージ618を受信した場合、ステップS104で生成されたランダム値と、記憶部208に記憶されている認証コード662とを用いてPINコードを生成する(S123)。次に、無線通信装置101は、生成されたPINコードを無線パラメータ自動設定アプリケーションに設定する(S124)。次に、無線通信装置101は、設定情報通知プロトコルを開始するためにプロトコル開始要求メッセージ619をアクセスポイント102に送信する(S125)。
 アクセスポイント102は、無線通信装置101からプロトコル開始要求メッセージ619を受信した場合、プロトコル開始メッセージ620を無線通信装置101に送信する(S126)。そして、無線通信装置101とアクセスポイント102は、WPSの登録プロトコルに従いプロトコルメッセージ621を交換する(S127)。ここで、無線通信装置101に設定されたPINコードとアクセスポイント102に設定されたPINコードとが一致することが、無線通信装置101とアクセスポイント102の双方で確認された場合のみ、アクセスポイント102の無線パラメータが無線通信装置101に送信され、送信された無線パラメータが無線通信装置101に設定される。
 次に、アクセスポイント102は、設定情報通知プロトコルが終了した後、プロトコル終了メッセージ622を無線通信装置101に送信し(S128)、WPS成功メッセージ623をサーバ103に送信する(S129)。サーバ103は、WPS成功メッセージ623を受信した場合、無線通信装置101にインターネットへの接続を許可する処理を行う(S130)。
 無線通信装置101は、プロトコル終了メッセージ622を受信した場合、一旦、ネットワークを離脱し、アクセスポイント102から取得したパラメータを用いることにより、再びアクセスポイント102の無線ネットワークに接続する(S131)。ここで、無線通信装置101には、アクセスポイント102と共通の暗号鍵及び認証鍵等が設定されている。よって、無線通信装置101は、暗号及び認証を用いた通常のデータ通信をおこなうことが可能である。
 また、サーバ103は、接続を許可する処理を行った後、アクセスポイント102に接続許可メッセージ624Aを送信する(S132)。アクセスポイント102は、接続許可メッセージ624Aを受信した場合、無線通信装置105に接続許可メッセージ624Bを送信する(S133)。無線通信装置105は、接続許可メッセージ624Bを受信した場合、例えば、図19に示す、無線通信装置101とアクセスポイント102との無線接続認証が完了した旨を示すメッセージ654を、ユーザに表示する。
 以上のように、本実施の形態に係る通信システム100は、無線通信装置101とアクセスポイント102との無線接続認証を行う。具体的には、無線通信装置101が、接続要求メッセージ611を第1無線アクセスポイント(アクセスポイント102又はアクセスポイント102A)に送信する(S105)。接続要求メッセージ611を受信したアクセスポイント102(又はアクセスポイント102A)が、当該第1無線アクセスポイントを示すアクセスポイント情報664を含む接続要求メッセージ612をサーバ103に送信する(S106)。
 次に、第1無線アクセスポイントと同一又は異なる第2無線アクセスポイント(アクセスポイント102)と無線接続認証が既に完了している無線通信装置105が、参加確認メッセージ613を第2無線アクセスポイントに送信する(S110)。参加確認メッセージ613を受信した第2無線アクセスポイントが、当該第2無線アクセスポイントを示すアクセスポイント情報665を含む参加確認メッセージ614をサーバ103に送信する(S111)。
 次に、サーバ103が、アクセスポイント情報664で示される第1無線アクセスポイントと、アクセスポイント情報665で示される第2無線アクセスポイントとを比較し、その結果、第1無線アクセスポイントと第2無線アクセスポイントとが同一の無線アクセスポイントである場合、当該同一の無線アクセスポイントを、無線通信装置101の接続先の無線アクセスポイントである接続先アクセスポイントに決定する(S112)。
 最後に、接続先アクセスポイントと無線通信装置101とが無線接続認証を行う(S125~S128)。
 以上により、サーバ103は、無線通信装置101が通信可能な複数の無線アクセスポイント(例えば、アクセスポイント102及び102A)が存在する場合であっても、無線通信装置105から送信された参加確認メッセージ613に従い接続対象の無線アクセスポイント(アクセスポイント102)が送信したアクセスポイント情報665を用いて、無線通信装置101の接続対象の無線アクセスポイントを適切に決定できる。
 また、ユーザは、無線通信装置101に接続要求メッセージ611を送信させる操作と、無線通信装置105に参加確認メッセージ613を送信させる操作とのみを行えばよい。例えば、ユーザは、図8に示すように、無線通信装置101(冷蔵庫)に設けられている操作ボタン651を押し、その後、図14に示すように、無線通信装置105(スマートフォン)において操作メニュー652を選択するという簡単な操作のみを行えばよい。このように、本実施の形態に係る無線接続認証方法は、ユーザが簡単な操作で無線接続認証を行うことができる。
 一方、ユーザが、ネットワーク内に存在する複数のアクセスポイントの中から所望のアクセスポイントを選択する場合には、ユーザが、機器の設定等に不慣れな場合には、適切に所望のアクセスポイントを選択することが困難な場合がある。
 また、ユーザがアクセスポイントに設けられているボタン等を操作する場合には、無線通信機器(例えば家電機器)とアクセスポイントとが離れて配置されている場合もある。このような場合には、ユーザは、離れて配置されている無線通信機器とアクセスポイントとの両方の操作を行う必要があり、ユーザにとって手間がかかるという課題がある。さらに、アクセスポイントの設置場所によっては、アクセスポイントに設けられているボタン等を容易に操作できない場合もある。一方で、本実施の形態では、例えば、ユーザが所有するスマートフォンを操作ればよいので、ユーザの手間を低減できる。
 さらに、本実施の形態では、アクセスポイントにボタン等を設ける必要がないので、システム全体のコストを低減できる。また、ユーザ操作が簡略化されることにより、不慣れなユーザによる不必要な操作の発生を低減できるので、機器の劣化又は故障を抑制できるとともに、不要な電力消費を低減できる。
 このように、本実施の形態では、既に所望のアクセスポイントとの接続を確立している端末を用いて新たにネットワークに接続する端末の無線パラメータが設定される。また、サーバ103は、新たにネットワークに接続する端末と、既に所望のアクセスポイントとの接続を確立している端末とから送信されたメッセージに、同一のアクセスポイントを示す情報が含まれるかを判断する。これにより、無線通信を行うことができるアクセスポイントが複数存在する場合であっても、意図しないアクセスポイントに接続されることを防止できる。また、ユーザがアクセスポイントを選択する必要がないので、ユーザの操作性が向上する。
 さらに、無線通信装置105は、ユーザ操作に応じて、無線通信装置101に固有の認証コード666(第1コード)を取得する(S115)。次に、無線通信装置105は、認証コード666をサーバ103に送信する(S116及びS117)。具体的には、無線通信装置105は、認証コード666を含む認証コード情報メッセージ616A(616B)を、アクセスポイント102を介してサーバ103に送信する。
 また、サーバ103は、認証コード666を用いて、無線通信装置101と接続先アクセスポイント(アクセスポイント102)との無線接続認証に用いられるPINコード667(第2コード)を生成する(S119)。次に、サーバ103は、PINコード667をアクセスポイント102に送信する(S120)。
 また、無線通信装置101が、認証コード666と同一の認証コード662(第3コード)を用いてPINコード(第4コード)を生成する(S123)。無線通信装置101及びアクセスポイント102は、認証コード662と、無線通信装置101で生成された認証コードとが同一であるか否かに応じて、無線通信装置101及びアクセスポイント102との無線接続認証を行う(S125~S128)。
 これにより、無線LANにおいて無線通信装置101とアクセスポイント102に安全かつ自動的に同一のPINコードを設定することができる。また、例えば、無線通信装置101が保持している認証コード662と、無線通信装置105に対してユーザが入力した認証コード666とを用いて、2つのPINコードが生成されるので、意図しない機器が誤って認証されることを防止できる。
 さらに、無線通信装置101は、ランダム値663(第5コード)を生成する(S104)。また、接続要求メッセージ611及び612の各々は、さらに、ランダム値663を含む。
 サーバ103は、認証コード666及びランダム値663を用いてPINコード667を生成する(S119)。無線通信装置101は、認証コード662及びランダム値663を用いて認証コードを生成する(S123)。
 これにより、設定されるPINコードが、ランダム値及び認証コードを用いて生成されるため、設定ごとに異なるPINコードが生成される。これにより、安全性を向上できる。さらに、認証コードは暗号化されたネットワークでのみ通信されるため、安全性が高い。
 また、認証コードの入力には新たにネットワークに接続する無線通信装置101(例えば家電機器)が用いられず、無線通信装置105(例えばスマートフォン)が用いられる。これにより、キーボード又はタッチパネルを有さないようなユーザインターフェースが乏しい無線通信装置101に対しても無線パラメータを設定することが可能である。
 次に、各装置における処理の流れを説明する。まず、無線通信装置101が設定情報通知プロトコルを実行する際の処理手順を、図20を用いて説明する。
 図20は、本実施の形態における無線通信装置101の処理を示すフローチャートである。なお、この処理は、アクセスポイント102が構築する無線ネットワークに無線通信装置101が接続した際に開始される。なお、この時点では、無線通信装置101とアクセスポイント102には共通の暗号鍵及び認証鍵等が設定されていない。そのため、無線通信装置101は、アクセスポイント102の無線ネットワークにおいて特定の信号(報知信号及びEAPパケット等)のみでしかアクセスポイント102と通信できない状態であり、暗号及び認証を用いた通常のデータ通信を行うことはできない。ここでは、無線通信装置101及びアクセスポイント102の間においてEAPパケットを用いて各種メッセージの送受信が行われる。
 まず、無線通信装置101は、PINコードの生成に必要なランダム値663を生成する(S201)。そして、無線通信装置101は、ランダム値663とID661とを含む接続要求メッセージ611をアクセスポイント102に送信する(S202)。無線通信装置101は、接続要求メッセージ611の送信後、アクセスポイント102からPINコード生成完了メッセージ618を受信するか、プロトコル失敗メッセージを受信するまで待機する(S203及びS204)。無線通信装置101は、プロトコル失敗メッセージを受信した場合(S204でYES)、この処理を終了する。
 また、無線通信装置101は、PINコード生成完了メッセージ618を受信した場合(S203でYES)、認証コード662(パスワード)と予め生成したランダム値663とを用いてPINコードを生成する(S205)。PINコードを生成する方法は暗号アルゴリズム又はハッシュアルゴリズムを用いる方法など、いずれの方法でもよい。
 無線通信装置101は、PINコードを生成した後、無線パラメータ自動設定アプリケーションにPINコードを設定する(S206)。そして、無線通信装置101は、設定したPINコードを用いて設定情報通知プロトコルを実行する(S207)。設定情報通知プロトコルでは、エンローリーとレジストラが互いのPINコードが一致するか否かを判定することにより、互いの正当性を認証する。そのため、エンローリーは同一のPINコードを持つレジストラから無線パラメータを取得することができる。
 無線通信装置101は、設定情報通知プロトコルが終了した後、設定情報通知プロトコルが成功したか否かを判断する(S208)。ここで、設定情報通知プロトコルの成功とは、エンローリーのPINコードと一致するPINコードを保持するレジストラからの無線パラメータの取得が完了したことを示す。設定情報通知プロトコルが失敗した場合(S208でNO)、無線通信装置101はこの処理を終了する。
 一方、設定情報通知プロトコルが成功した場合(S208でYES)、無線通信装置101は、取得した無線パラメータを用いてアクセスポイント102が構築している無線ネットワークに接続する(S209)。こうすることにより、無線通信装置101には、アクセスポイント102と共通の暗号鍵及び認証鍵等が設定される。これにより、無線通信装置101は、暗号及び認証を用いた通常のデータ通信を行うことが可能となる。
 次に、アクセスポイント102が設定情報通信プロトコルを実行する際の処理手順を、図21、図22及び図23を用いて説明する。
 図21、図22及び図23は、本実施の形態におけるアクセスポイント102の処理を示すフローチャートである。なお、この処理はアクセスポイント102が構築している無線ネットワークに無線パラメータ自動設定の実行を要求する無線通信装置101が参加した際に開始される。なお、この時点では、無線通信装置101とアクセスポイント102には共通の暗号鍵及び認証鍵等が設定されていない。そのため、無線通信装置101は、アクセスポイント102の無線ネットワークにおいて特定の信号(報知信号及びEAPパケット等)のみでしかアクセスポイント102と通信できない状態であり、暗号及び認証を用いた通常のデータ通信を行うことはできない。ここでは、無線通信装置101及びアクセスポイント102の間においてEAPパケットを用いて各種メッセージの送受信が行われる。
 まず、アクセスポイント102は、無線通信装置101から接続要求メッセージ611を受信するのを待つ(S301)。アクセスポイント102は、無線通信装置101から接続要求メッセージ611を受信した場合(S301でYES)、接続要求メッセージ611に含まれるランダム値663及びID661と、当該アクセスポイント102を示すアクセスポイント情報664とを含む接続要求メッセージ612をサーバ103に送信する(S302)。
 アクセスポイント102は、接続要求メッセージ612を送信した後、既にアクセスポイント102との接続を確立している無線通信装置105から参加確認メッセージ613を受信するか、サーバ103から拒否通知メッセージを受信するまで待つ(S303及びS304)。
 アクセスポイント102は、拒否通知メッセージを受信した場合(S304でYES)、プロトコル失敗メッセージを無線通信装置101に送信し(S305)、この処理を終了する。ここで、無線通信装置105及びアクセスポイント102には共通の暗号鍵及び認証鍵等が設定されているため、無線通信装置105及びアクセスポイント102は、暗号及び認証を用いた通常のデータ通信を行うことができる。
 アクセスポイント102は、無線通信装置105から参加確認メッセージ613を受信した場合(S303でYES)、当該アクセスポイント102を示すアクセスポイント情報665を含む参加確認メッセージ614をサーバ103に送信する(S306)。アクセスポイント102は、参加確認メッセージ614を送信した後、サーバ103から認証コード要求メッセージ615Aを受信するか、拒否通知メッセージを受信するまで待つ(S307及びS308)。アクセスポイント102は、拒否通知メッセージを受信した場合(S308でYES)、プロトコル失敗メッセージを無線通信装置101に送信し、拒否通知メッセージを無線通信装置105に送信し(S309)、この処理を終了する。
 アクセスポイント102は、認証コード要求メッセージ615Aを受信した場合(S307でYES)、無線通信装置105に認証コード要求メッセージ615Bを送信する(S310)。アクセスポイント102は、認証コード要求メッセージ615Bを送信した後、無線通信装置105から認証コード666を含む認証コード情報メッセージ616Aを受信するまで待つ(S311)。ここで、認証コード666とは無線通信装置101に固有の数字又は文字列である。
 アクセスポイント102は、認証コード情報メッセージ616Aを受信した場合(S311でYES)、認証コード情報メッセージ616Aに含まれる認証コード666を含む認証コード情報メッセージ616Bをサーバ103に送信する(S312)。アクセスポイント102は、認証コード情報メッセージ616Bを送信した後、サーバ103からPINコード情報メッセージ617を受信するか、拒否通知メッセージを受信するまで待つ(S313及びS314)。アクセスポイント102は、拒否通知メッセージを受信した場合(S314でYES)、プロトコル失敗メッセージを無線通信装置101に送信し、拒否通知メッセージを無線通信装置105に送信し(S315)、この処理を終了する。
 一方、アクセスポイント102は、PINコード情報メッセージ617を受信した場合(S313でYES)、PINコード情報メッセージ617に含まれるPINコード667を無線パラメータ自動設定アプリケーションに設定する(S316)。そして、アクセスポイント102は、無線通信装置101にPINコード生成完了メッセージ618を送信する(S317)。次に、アクセスポイント102は、設定したPINコード667を用いて設定情報通知プロトコルを無線通信装置101との間で実行する(S318)。
 次に、アクセスポイント102は、設定情報通知プロトコルが成功したか否かを判断する(S319)。ここで、設定情報通知プロトコルの成功とは、レジストラが保持するPINコードとエンローリーが保持するPINコードとが一致し、レジストラからエンローリーに対しての無線パラメータの提供が完了した場合を示す。設定情報通知プロトコルが成功した場合(S319でYES)、アクセスポイント102は、WPS成功メッセージ623をサーバ103に送信する(S320)。アクセスポイント102は、WPS成功メッセージを送信した後、サーバ103から接続許可メッセージ624Aを受信するまで待つ(S321)。アクセスポイント102は、接続許可メッセージ624Aを受信した場合(S321でYES)、接続許可メッセージ624Bを無線通信装置105に送信し(S322)、この処理を終了する。
 一方、設定情報通知プロトコルが失敗した場合(S319でNO)、アクセスポイント102は、WPS失敗メッセージをサーバ103に送信する(S323)。アクセスポイント102は、WPS失敗メッセージを送信した後、サーバ103から接続失敗メッセージを受信するまで待つ(S324)。アクセスポイント102は、接続失敗メッセージを受信した場合(S324でYES)、接続失敗メッセージを無線通信装置105に送信し(S325)、この処理を終了する。
 次に、無線通信装置101がインターネット104に接続する際に、認証を行うサーバ103の処理手順を、図24及び図25を用いて説明する。図24及び図25は本実施の形態におけるサーバ103の処理を示すフローチャートである。
 まず、サーバ103は、アクセスポイント102から接続要求メッセージ612を受信するのを待つ(S401)。サーバ103は、アクセスポイント102から接続要求メッセージを受信した場合(S401でYES)、接続要求メッセージ612に含まれるID661が有効なIDであるか否かを確認する(S402)。例えば、サーバ103は、記憶部408に保存しているアカウント管理情報を参照し、予め有効なIDとして登録されたIDと受信したID661とが一致すれば、受信したID661は有効と判断する。
 ここで、受信したID661が無効であった場合(S402でNO)、サーバ103は、拒否通知メッセージをアクセスポイント102に送信し(S416)、この処理を終了する。一方、受信したID661が有効であった場合(S402でYES)、サーバ103は、接続要求メッセージ611を送信した無線通信装置101のID661を登録する(S403)。
 次に、サーバ103は、アクセスポイント102から参加確認メッセージ614を受信するまで待つ(S404)。サーバ103は、参加確認メッセージ614を受信した場合(S404でYES)、参加確認メッセージ614に含まれるアクセスポイント情報665で示されるアクセスポイントが、接続要求メッセージ612に含まれるアクセスポイント情報664で示されるアクセスポイントと同一か否かを確認する(S405)。
 ここで、アクセスポイントが異なる場合(S405でNO)、サーバ103はアクセスポイント102からの参加確認メッセージ614を受信するまで待つ(S404)。一方、アクセスポイントが同一、すなわち、参加確認メッセージ614がアクセスポイント102から送信されていた場合(S405でYES)、サーバ103はアクセスポイント102に認証コード要求メッセージ615Aを送信する(S406)。
 次に、サーバ103はアクセスポイント102から認証コード情報メッセージ616Bを受信するまで待つ(S407)。サーバ103は、アクセスポイント102から認証コード情報メッセージ616Bを受信した場合(S407でYES)、認証コード情報メッセージ616Bに含まれる認証コード666が、接続要求が行われたIDに紐付けされた認証コードであるか否かを確認する(S408)。例えば、サーバ103は、記憶部408に保存しているアカウント管理情報を参照し、予めIDに紐付けされた認証コードと受信した認証コード666とが一致すれば、受信した認証コード666は有効と判断する。ここで、認証コードは無線通信装置101に固有のコードであるため、この処理により、無線通信装置105の正当性を確認することができる。
 ここで、受信した認証コード666が無効であった場合(S408でNO)、サーバ103は拒否通知メッセージをアクセスポイント102に送信し(S416)、この処理を終了する。一方、受信した認証コードが有効であった場合(S408でYES)、サーバ103は接続要求メッセージ612に含まれるランダム値663と、認証コード情報メッセージ616Bに含まれる認証コード666とを用いてPINコード667を生成する(S409)。
 次に、サーバ103は、生成したPINコード667を含むPINコード情報メッセージ617をアクセスポイント102に送信する(S410)。PINコード情報メッセージ617を送信した後、サーバ103は、アクセスポイント102からWPS成功メッセージ623を受信するか、WPS失敗メッセージを受信するのを待つ(S411及びS412)。
 サーバ103は、WPS成功メッセージ623を受信した場合(S411でYES)、無線通信装置101にインターネット104への接続を許可する処理を行う(S414)。次に、サーバ103は、アクセスポイント102に接続許可メッセージ624Aを送信し(S415)、この処理を終了する。また、サーバ103は、WPS失敗メッセージを受信した場合(S412でYES)、アクセスポイント102に接続失敗メッセージを送信し(S413)、この処理を終了する。
 次に、無線通信装置101がインターネット104に接続する際に、認証手続きを行う無線通信装置105の処理手順を、図26を用いて説明する。
 図26は、本実施の形態における無線通信装置105の処理を示すフローチャートである。なお、無線通信装置105とアクセスポイント102には既に共通の暗号鍵及び認証鍵等が設定されている。そのため、無線通信装置105はアクセスポイント102の無線ネットワークにおいて暗号及び認証を用いた通常のデータ通信を行うことができる。
 まず、無線通信装置105は、参加確認メッセージ613をアクセスポイント102に送信し(S501)、アクセスポイント102から認証コード要求メッセージ615Bを受信するのを待つ(S502)。
 無線通信装置105は、認証コード要求メッセージ615Bを受信した場合(S502でYES)、ユーザの操作等に応じて認証コード666を生成する(S503)。ここで、認証コード666とは無線通信装置101固有の数字又は文字列である。次に、無線通信装置105は、生成した認証コード666を含む認証コード情報メッセージ616Aをアクセスポイント102に送信する(S504)。
 無線通信装置105は、認証コード情報メッセージ616Aを送信した後、アクセスポイント102から接続許可メッセージ624Bを受信するか、拒否通知メッセージを受信するか、接続失敗メッセージを受信するのを待つ(S505、S506及びS507)。無線通信装置105は、アクセスポイント102から接続許可メッセージ624Bを受信するか、拒否通知メッセージを受信するか、接続失敗メッセージを受信した場合(S505でYES、S506でYES又はS507でYES)、この処理を終了する。
 (実施の形態2)
 次に図面を参照しながら実施の形態2を詳細に説明する。上記実施の形態1では、ユーザにより、無線通信装置101の操作が行われた後、既にアクセスポイント102と通信を確立している無線通信装置105の操作が行われた。本実施の形態では、ユーザにより、無線通信装置105の操作が行われた後に、無線通信装置101の操作が行われる。
 なお、本実施の形態における通信システム100の構成の概要、並びに、無線通信装置101、アクセスポイント102、サーバ103、及び既にアクセスポイント102と通信を確立している無線通信装置105の構成の概要は、図1から図5を用いて説明した実施の形態1と同じであり、説明は省略する。
 以下、無線通信装置101、アクセスポイント102、サーバ103及び無線通信装置105の間で行われるアカウント認証シーケンスを、図27及び図28を用いて説明する。
 図27及び図28は、本実施の形態におけるアカウント認証シーケンスを示すシーケンス図である。なお、以下の図では、既に説明した処理と同様の処理には同一の符号を付しており、重複する説明を省略する場合がある。
 まず、既にアクセスポイント102と接続が確立している無線通信装置105において、ユーザの操作等に応じて参加登録アプリケーションが起動される(S109)。次に、無線通信装置105は、参加要求メッセージ613Aをアクセスポイント102に送信する(S110A)。アクセスポイント102は、参加要求メッセージ613Aを受信した場合、参加要求メッセージ613Aにアクセスポイント情報665を付加することで参加要求メッセージ614Aを生成し、生成された参加要求メッセージ614Aをサーバ103に送信する(S111A)。なお、参加要求メッセージ614Aの構成は、例えば、図15に示す参加確認メッセージ614の構成と同様である。次に、サーバ103は、アクセスポイント102に認証コード要求メッセージ615Aを送信する(S113)。なお、ステップS113~S117の処理は図6で説明した処理と同じであり、説明は省略する。
 サーバ103は、アクセスポイント102から認証コード情報メッセージ616Bを受信した場合、受信した認証コード情報メッセージ616Bに含まれる認証コード666の有効性を確認する(S118)、認証コード666が有効である場合は、サーバ103は、受信した認証コード666に紐付けされたIDを持つ無線通信装置101をアクセスポイント102への接続要求がある端末として登録する(S108A)。次に、無線通信装置101において、ユーザの操作等によって無線パラメータ自動設定アプリケーションが起動される(S101)。なお、ステップS101~S106の処理は図6で説明した処理と同じであり、説明は省略する。
 サーバ103は、アクセスポイント102から接続要求メッセージ612を受信した場合、アクセスポイント102への接続要求がある端末が存在するかを確認する。具体的には、サーバ103は、参加確認メッセージ614に含まれるアクセスポイント情報665で示されるアクセスポイントと、接続要求メッセージ612に含まれるアクセスポイント情報664で示されるアクセスポイントとが同一であるか否かを確認する(S112)。端末が存在する場合(アクセスポイント情報665及び664で示されるアクセスポイントが同一である場合)、サーバ103は、受信した接続要求メッセージ612に含まれるID661の有効性を確認し(S107)、ID661が有効である場合は、アクセスポイント102への接続要求がある端末である無線通信装置101の無線パラメータ設定のためのPINコードを、接続要求メッセージ612に含まれていたランダム値663と、認証コード情報メッセージ616Bに含まれていた認証コード666を用いて生成する(S119)。なお、これ以降の処理(S120~S133)は図7で説明した処理と同じであり、説明は省略する。
 本実施の形態によれば、実施の形態1の効果に加え、無線通信装置105が新たに無線ネットワークに参加する無線通信装置を予め登録することで、無線通信装置101が無線ネットワーク参加要求を行う場合に、速やかに無線パラメータの設定を行うことができる。
 次に、各装置における処理の流れを説明する。なお、本実施の形態における無線通信装置101が設定情報通知プロトコルを実行する際の処理手順は、図20を用いて説明した実施の形態1と同じであり、説明は省略する。
 次に、アクセスポイント102が設定情報通信プロトコルを実行する際の処理手順を、図29、図30及び図31を用いて説明する。図29、図30及び図31は本実施の形態におけるアクセスポイント102の処理を示すフローチャートである。
 まず、アクセスポイント102は、無線通信装置105から参加要求メッセージ613Aを受信するのを待つ(S303A)。アクセスポイント102は、参加要求メッセージ613Aを受信した場合(S303AでYES)、当該アクセスポイント102を示すアクセスポイント情報665を含む参加要求メッセージ614Aをサーバ103に送信する(S306A)。
 アクセスポイント102は、参加要求メッセージ614Aを送信した後、サーバ103から認証コード要求メッセージ615Aを受信するのを待つ(S307)。アクセスポイント102は、認証コード要求メッセージ615Aを受信した場合(S307でYES)、無線通信装置105に認証コード要求メッセージ615Bを送信する(S310)。なお、ステップS310~S312の処理は図22で説明した処理と同じであり、説明は省略する。
 アクセスポイント102は、認証コード情報メッセージ616Bを送信した後、サーバ103から拒否通知メッセージを受信するか、無線通信装置101から接続要求メッセージ611を受信するまで待つ(S304及びS301)。アクセスポイント102は、拒否通知メッセージを受信した場合(S304でYES)、無線通信装置105に拒否通知メッセージを送信し(S305A)、この処理を終了する。
 一方、アクセスポイント102は、無線通信装置101から接続要求メッセージ611を受信した場合(S301でYES)、接続要求メッセージ611に含まれるランダム値663及びID661と、当該アクセスポイント102を示すアクセスポイント情報664とを含む接続要求メッセージ612をサーバ103に送信する(S302)。なお、以降の処理(S313~S325)は図22及び図23で説明した処理と同じであり、説明は省略する。
 次に、無線通信装置101がインターネット104に接続する際に、認証を行うサーバ103の処理手順を、図32及び図33を用いて説明する。図32及び図33は本実施の形態におけるサーバ103の処理を示すフローチャートである。
 まず、サーバ103は、アクセスポイント102から参加要求メッセージ614Aを受信するのを待つ(S404A)。サーバ103は、アクセスポイント102から参加要求メッセージ614Aを受信した場合(S404AでYES)、アクセスポイント102に認証コード要求メッセージ615Aを送信する(S406)。なお、ステップS406~S407の処理は図24で説明した説明した処理と同じであり、説明は省略する。
 サーバ103は、認証コード情報メッセージ616Bを受信した場合(S407でYES)、認証コード情報メッセージ616Bに付加されている認証コード666が、有効な認証コードか否かを確認する(S408)。例えば、サーバ103は、記憶部408に保存しているアカウント管理情報を参照し、予め有効なIDとして登録されたIDに紐付けされた認証コードと受信した認証コード666とが一致すれば、受信した認証コードは有効と判断する。
 ここで、受信した認証コード666が無効であった場合(S408でNO)、サーバ103は拒否通知メッセージをアクセスポイント102に送信し(S416)、この処理を終了する。一方、受信した認証コードが有効であった場合(S408でYES)、サーバ103は認証コード666に紐付けされた無線通信装置のIDを登録する(S403A)。
 サーバ103は、無線通信装置のIDを登録した後、アクセスポイント102から接続要求メッセージ612を受信するのを待つ(S401)。サーバ103は、接続要求メッセージ612を受信した場合(S401でYES)、接続要求メッセージ612に含まれるアクセスポイント情報664で示されるアクセスポイントが、参加要求メッセージ614Aに含まれるアクセスポイント情報665で示されるアクセスポイントと同一か否かを確認する(S405)。
 ここで、アクセスポイントが異なる場合(S405でNO)、サーバ103はアクセスポイント102からの接続要求メッセージ612を受信するまで待つ(S401)。アクセスポイントが同一、すなわち接続要求メッセージ612がアクセスポイント102から送信されていた場合(S405でYES)、サーバ103は接続要求メッセージ612に含まれるID661が有効なIDであるか否か確認する(S402)。例えば、サーバ103は、記憶部408に保存しているアカウント管理情報を参照し、予め有効なIDとして登録されたIDと受信したID661が一致すれば、受信したID661は有効と判断する。
 ここで、受信したIDが無効である場合(S402でNO)、サーバ103は、拒否通知メッセージをアクセスポイント102に送信し(S416)、この処理を終了する。一方、受信したID661が有効であった場合(S402でYES)、サーバ103は、接続要求メッセージ612に含まれるランダム値663と、認証コード情報メッセージ616Bに含まれる認証コード666とを用いてPINコード667を生成する(S409)。なお、これ以降の処理(S410~S415)は図25で説明した処理と同じであり、説明は省略する。
 次に、無線通信装置101がインターネット104に接続する際に、認証手続きを行う無線通信装置105の処理手順を、図34を用いて説明する。図34は本実施の形態における無線通信装置105の処理を示すフローチャートである。
 まず、無線通信装置105はアクセスポイント102に参加要求メッセージ613Aを送信する(S501A)。なお、これ以降の処理(S502~S507)は図26で説明した処理と同じであり、説明は省略する。
 (実施の形態3)
 次に図面を参照しながら実施の形態3を詳細に説明する。本実施の形態では、上記実施の形態1の変形例を説明する。本実施の形態では、無線通信装置101は、接続要求メッセージ611を送信した後に、無線信号を送信する。そして、無線通信装置105は、無線通信装置101から送信される無線信号を受信した場合に、参加確認メッセージ613を送信する。これにより、参加確認メッセージ613が誤って送信されることを防止できる。
 なお、本実施の形態における通信システム100の構成の概要、並びに、アクセスポイント102、サーバ103、及び既にアクセスポイントの通信を確立している無線通信装置105の構成の概要は、図1、図3、図4、及び図5を用いて説明した実施の形態1と同じであり、説明は省略する。
 図35は、本実施の形態における無線通信装置101の構成の一例を示すブロック図である。図35に示す無線通信装置101は、図2に示す構成に加え、出力信号強度制御部209と、計時部210とを備える。出力信号強度制御部209は、無線信号の出力強度を制御する。計時部210は、タイマ処理及び時刻を管理する。
 次に、無線通信装置101、アクセスポイント102、サーバ103及び無線通信装置105の間で行われるアカウント認証シーケンスを、図36及び図37を用いて説明する。
 図36及び図37は、本実施の形態におけるアカウント認証シーケンスを示すシーケンス図である。なお、ステップS101~S108の処理は図6で説明した処理と同じであり、説明は省略する。
 無線通信装置101は、接続要求メッセージ611をアクセスポイント102に送信した後、無線信号(ビーコン)の送出を開始する(S141)。無線通信装置101は,PINコード生成完了メッセージ618を受信するまで、無線信号の送信強度を徐々に大きくする。
 また、既にアクセスポイント102と接続が確立している無線通信装置105において、ユーザの操作等によって参加登録アプリケーションが起動された後、無線通信装置105は、無線通信装置101から無線信号を受信するのを待つ(S143)。無線通信装置105は、無線信号を受信した場合に、参加確認メッセージ613をアクセスポイント102に送信する(S110)。なお、これ以降の処理(S111~S133)は図6及び図7で説明した処理と同じであり、説明は省略する。
 以上のように、本実施の形態では、無線通信装置101は、接続要求メッセージ611を第1無線アクセスポイント(例えば、アクセスポイント102又は102A)に送信した後に、無線信号を送信する(S142)。無線通信装置105は、上記無線信号を受信した場合(S143)に、参加確認メッセージ613を第2無線アクセスポイント(アクセスポイント102)に送信する(S110)。
 このように、既にアクセスポイント102との接続を確立している無線通信装置105が新たに無線ネットワークに参加する無線通信装置101から送信される無線信号を受信するまで、参加確認メッセージを送信しない。これにより、実施の形態1の効果に加え、新規登録を要求する無線通信装置101と離れた位置にいるユーザから、誤って参加確認メッセージ613が送信されることを防ぐことができる。
 次に、各装置における処理の流れを説明する。まず、本実施の形態における無線通信装置101が設定情報通知プロトコルを実行する際の処理手順を、図38を用いて説明する。
 なお、ステップS201及びS202の処理は図20で説明した処理と同じであり、説明は省略する。無線通信装置101は、接続要求メッセージ611を送信した後、無線信号(ビーコン)の送信を開始する(S210)。
 無線通信装置101は、無線信号の送信を開始後、アクセスポイント102からPINコード生成完了メッセージ618を受信したか否かを判断する(S203)。無線通信装置101は、PINコード生成完了メッセージ618を受信していない場合(S203でNO)、アクセスポイント102からプロトコル失敗メッセージを受信したか否かを判断する(S204)。無線通信装置101は、プロトコル失敗メッセージを受信した場合(S204でYES)、この処理を終了する。
 無線通信装置101は、プロトコル失敗メッセージを受信していない場合(S204でNO)、現在の無線信号の送信出力強度が上限値であるか否かを判断する(S211)。送信出力強度が上限値である場合(S211でYES)、無線通信装置101はステップS203に戻る。送信出力強度が上限値でない場合(S211でNO)、無線通信装置101は、無線信号の送信出力強度を変更してから一定時間が経過しているか否かを判断する(S212)。一定時間が経過していない場合(S212でNO)、無線通信装置101はステップS203に戻る。一定時間が経過している場合(S212でYES)、無線通信装置101は無線信号の送信出力強度を上げ(S213)、ステップS203に戻る。
 一方、無線通信装置101は、アクセスポイント102からPINコード生成完了メッセージ618を受信した場合(S203でYES)、認証コード662とランダム値663とを用いてPINコードを生成する(S205)。なお、ステップS206~S209の処理は図20で説明した処理と同じであり、説明は省略する。
 なお、本実施の形態におけるアクセスポイント102が設定情報通信プロトコルを実行する際の処理手順は図21、図22及び図23で説明した実施の形態1と同じであり、説明は省略する。
 また、本実施の形態における無線通信装置101がインターネット104に接続する際に、認証を行うサーバ103の処理手順は図24及び図25で説明した実施の形態1と同じであり、説明は省略する。
 次に、無線通信装置101がインターネット104に接続する際に、認証手続きを行う無線通信装置105の処理手順を、図39を用いて説明する。
 図39は、本実施の形態における無線通信装置105の処理を示すフローチャートである。なお、無線通信装置105とアクセスポイント102には既に共通の暗号鍵及び認証鍵等が設定されている。そのため、無線通信装置105はアクセスポイント102の無線ネットワークにおいて暗号及び認証を用いた通常のデータ通信を行うことができる。
 まず、無線通信装置105は、無線通信装置101から無線信号を受信するまで待つ(S510)。無線通信装置105は、無線通信装置101から無線信号を受信した場合(S510でYES)、アクセスポイント102に参加確認メッセージ613を送信する(S501)。なお、これ以降の処理(S502~S507)は図26で説明した処理と同じであり、説明は省略する。
 以上、実施の形態1~3で説明したように、本実施の形態に係るサーバ103は、第1無線通信装置(無線通信装置101)と無線アクセスポイント(アクセスポイント102)との通信を確立するための無線接続認証を行うサーバ103であって、図40に示す処理を行う。
 まず、サーバ103に含まれる第1受信部は、第1無線通信装置(無線通信装置101)から、第1無線アクセスポイント(例えば、アクセスポイント102又は102A)を示す第1アクセスポイント情報(アクセスポイント情報664)を受信する(S601)。具体的には、第1受信部は、第1アクセスポイント情報(アクセスポイント情報664)を含む第2メッセージ(接続要求メッセージ612)を受信する。また、第2メッセージ(接続要求メッセージ612)は、第1無線通信装置(無線通信装置101)から送信された第1メッセージ(接続要求メッセージ611)に従い第1無線アクセスポイント(例えば、アクセスポイント102又は102A)が送信したメッセージである。
 次に、サーバ103に含まれる第2受信部は、第1無線アクセスポイント(アクセスポイント102又は102A)と同一又は異なる第2無線アクセスポイント(アクセスポイント102)と既に通信が確立している第2無線通信装置(無線通信装置105)から、第2無線アクセスポイント(アクセスポイント102)を示す第2アクセスポイント情報(アクセスポイント情報665)を受信する(S602)。具体的には、第2受信部は、第2アクセスポイント情報を含む第4メッセージ(参加確認メッセージ614又は参加要求メッセージ614A)を受信する。また、第4メッセージ(参加確認メッセージ614又は参加要求メッセージ614A)は、第2無線通信装置(無線通信装置105)から送信された第3メッセージ(参加確認メッセージ613又は参加要求メッセージ613A)に従い、第2無線アクセスポイント(アクセスポイント102)が送信したメッセージである。
 なお、実施の形態1で説明したように、ステップS601の後にステップS602が行われてもよいし、実施の形態2で説明したように、ステップS602の後にステップS601が行われてもよい。
 次に、サーバ103に含まれる決定部は、第1アクセスポイント情報で示される第1無線アクセスポイントと、第2アクセスポイント情報で示される第2無線アクセスポイントとを比較する(S603)。そして、決定部は、第1無線アクセスポイントと第2無線アクセスポイントとが同一の無線アクセスポイントである場合(S603でYES)、当該同一の無線アクセスポイントを、第1無線通信装置の接続先の無線アクセスポイントである接続先アクセスポイントに決定する(S604)。
 次に、サーバ103に含まれる認証処理部は、上記接続先アクセスポイントと第1無線通信装置との無線接続認証を行うための処理を行う(S605)。例えば、認証処理部は、図24及び図25に示すステップS406~S416の処理を行う。
 なお、上記第1受信部及び第2受信部は、例えば、図4に示す通信部401及び通信制御部402等により実現される。また、決定部は、例えば、図4に示す判断部407等により実現される。認証処理部は、例えば、図4に示す認証処理部405により実現される。
 以上により、サーバ103は、第1無線通信装置(無線通信装置101)が通信可能な複数の無線アクセスポイント(例えば、アクセスポイント102及び102A)が存在する場合であっても、第2無線通信装置(無線通信装置105)から送信された第3メッセージに従い接続対象の無線アクセスポイント(アクセスポイント102)が送信した第2アクセスポイント情報を用いて、第1無線通信装置の接続対象の無線アクセスポイントを決定できる。また、ユーザは、第1無線通信装置に第1メッセージを送信させる操作と、第2無線通信装置に第3メッセージを送信させる操作とのみを行えばよい。このように、ユーザは、簡単な操作で無線接続認証を行うことができる。
 また、サーバ103は、第2無線通信装置から第1無線通信装置に固有の第1コード(認証コード666)を受信する。サーバ103は、第1コードを用いて、第1無線通信装置と接続先アクセスポイントとの無線接続認証に用いられる第2コード(PINコード667)を生成する。サーバ103は、第2コードを接続先アクセスポイントに送信する。これにより、意図しない機器が誤って認証されることを防止できる。
 また、第1メッセージ及び第2メッセージの各々は、さらに、第3コード(ランダム値663)を含む。サーバ103は、第1コード及び第3コードを用いて第2コードを生成する。なお、第3コードは、ランダム値663に限定されず、任意のコードであってもよい。これにより、意図しない機器が誤って認証されることを防止できる。
 以上、本発明の実施の形態に係る通信システムについて説明したが、本発明は、この実施の形態に限定されるものではない。
 例えば、上記実施の形態では、IEEE802.11の無線LANを例に説明したが、ワイヤレスUSB、又はBluetooth(登録商標)等の他の通信方式に本実施の形態を適用しても良い。
 また、上記実施の形態では、本実施の形態に係る特徴的な処理を行う通信システムについて説明したが、本発明は、上記通信システムに含まれる、無線通信装置、アクセスポイント、又は、サーバとして実現されてもよい。また、本発明は、通信システム、無線通信装置、アクセスポイント、又は、サーバにおける無線接続認証方法として実現されてもよい。
 また、上記各実施の形態において、各構成要素は、専用のハードウェアで構成されるか、各構成要素に適したソフトウェアプログラムを実行することによって実現されてもよい。各構成要素は、CPU又はプロセッサなどのプログラム実行部が、ハードディスク又は半導体メモリなどの記録媒体に記録されたソフトウェアプログラムを読み出して実行することによって実現されてもよい。ここで、上記各実施の形態のサーバなどを実現するソフトウェアは、次のようなプログラムである。
 すなわち、このプログラムは、コンピュータに、第1無線通信装置と無線アクセスポイントとの通信を確立するための無線接続認証を行うサーバにおける無線接続認証方法を実行させるプログラムである。このプログラムは、コンピュータに、前記第1無線通信装置から送信された第1メッセージに従い第1無線アクセスポイントが送信した、前記第1無線アクセスポイントを示す第1アクセスポイント情報を含む第2メッセージを受信する第1受信ステップと、前記第1無線アクセスポイントと同一又は異なる第2無線アクセスポイントと既に通信が確立している第2無線通信装置から送信された第3メッセージに従い、前記第2無線アクセスポイントが送信した、前記第2無線アクセスポイントを示す第2アクセスポイント情報を含む第4メッセージを受信する第2受信ステップと、前記第1アクセスポイント情報で示される前記第1無線アクセスポイントと、前記第2アクセスポイント情報で示される前記第2無線アクセスポイントとを比較し、前記第1無線アクセスポイントと前記第2無線アクセスポイントとが同一の無線アクセスポイントである場合、当該同一の無線アクセスポイントを、前記第1無線通信装置の接続先の無線アクセスポイントである接続先アクセスポイントに決定する決定ステップと、前記接続先アクセスポイントと前記第1無線通信装置との無線接続認証を行うための処理を行う認証処理ステップとを実行させる。
 さらに、本発明は上記プログラムであってもよいし、上記プログラムが記録された非一時的なコンピュータ読み取り可能な記録媒体であってもよい。また、上記プログラムは、インターネット等の伝送媒体を介して流通させることができるのは言うまでもない。
 また、ブロック図における機能ブロックの分割は一例であり、複数の機能ブロックを一つの機能ブロックとして実現したり、一つの機能ブロックを複数に分割したり、一部の機能を他の機能ブロックに移してもよい。また、類似する機能を有する複数の機能ブロックの機能を単一のハードウェア又はソフトウェアが並列又は時分割に処理してもよい。
 また、上記処理に含まれるステップが実行される順序は、本発明を具体的に説明するために例示するためのものであり、同様の結果が得られる範囲において上記以外の順序であってもよい。また、上記ステップの一部が、他のステップと同時(並列)に実行されてもよい。
 以上、一つまたは複数の態様に係る通信システムについて、実施の形態に基づいて説明したが、本発明は、この実施の形態に限定されるものではない。本発明の趣旨を逸脱しない限り、当業者が思いつく各種変形を本実施の形態に施したものや、異なる実施の形態における構成要素を組み合わせて構築される形態も、一つまたは複数の態様の範囲内に含まれてもよい。
 本発明は、無線LANの簡易接続方法等として有用である。また、本発明は、公衆無線LANの接続等の用途にも応用できる。
 100  通信システム
 101、105  無線通信装置
 102、102A  アクセスポイント
 103  サーバ
 104  インターネット
 201、301、401、501  通信部
 202、302、402、502  通信制御部
 203、303、403、503  装置制御部
 204、304、404、504  インターフェース処理部
 205、305、505  無線パラメータ設定処理部
 206、406  符号演算部
 207、306、407、506  判断部
 208、307、408、507  記憶部
 209  出力信号強度制御部
 210  計時部
 405  認証処理部
 508  表示部
 611、612  接続要求メッセージ
 613、614  参加確認メッセージ
 613A、614A  参加要求メッセージ
 615A、615B  認証コード要求メッセージ
 616A、616B  認証コード情報メッセージ
 617  PINコード情報メッセージ
 618  PINコード生成完了メッセージ
 619  プロトコル開始要求メッセージ
 620  プロトコル開始メッセージ
 621  プロトコルメッセージ
 622  プロトコル終了メッセージ
 623  WPS成功メッセージ
 624A、624B  接続許可メッセージ
 651  操作ボタン
 652  操作メニュー
 653  入力メニュー
 654  メッセージ
 661、671  ID
 662、666  認証コード
 663、672  ランダム値
 664、665、673  アクセスポイント情報
 667  PINコード

Claims (11)

  1.  第1無線通信装置と無線アクセスポイントとの通信を確立するための無線接続認証を行うサーバにおける無線接続認証方法であって、
     前記第1無線通信装置から送信された第1メッセージに従い第1無線アクセスポイントが送信した、前記第1無線アクセスポイントを示す第1アクセスポイント情報を含む第2メッセージを受信する第1受信ステップと、
     前記第1無線アクセスポイントと同一又は異なる第2無線アクセスポイントと既に通信が確立している第2無線通信装置から送信された第3メッセージに従い、前記第2無線アクセスポイントが送信した、前記第2無線アクセスポイントを示す第2アクセスポイント情報を含む第4メッセージを受信する第2受信ステップと、
     前記第1アクセスポイント情報で示される前記第1無線アクセスポイントと、前記第2アクセスポイント情報で示される前記第2無線アクセスポイントとを比較し、前記第1無線アクセスポイントと前記第2無線アクセスポイントとが同一の無線アクセスポイントである場合、当該同一の無線アクセスポイントを、前記第1無線通信装置の接続先の無線アクセスポイントである接続先アクセスポイントに決定する決定ステップと、
     前記接続先アクセスポイントと前記第1無線通信装置との無線接続認証を行うための処理を行う認証処理ステップとを含む
     無線接続認証方法。
  2.  前記無線接続認証方法は、さらに、
     前記第2無線通信装置から前記第1無線通信装置に固有の第1コードを受信する第3受信ステップを含み、
     前記認証処理ステップは、
     前記第1コードを用いて、前記第1無線通信装置と前記接続先アクセスポイントとの無線接続認証に用いられる第2コードを生成する第2コード生成ステップと、
     前記第2コードを前記接続先アクセスポイントに送信する送信ステップとを含む
     請求項1記載の無線接続認証方法。
  3.  前記第1メッセージ及び前記第2メッセージの各々は、さらに、第3コードを含み、
     前記第2コード生成ステップでは、前記第1コード及び前記第3コードを用いて前記第2コードを生成する
     請求項2記載の無線接続認証方法。
  4.  第1無線通信装置と無線アクセスポイントとの無線接続認証を行う無線接続認証方法であって、
     前記第1無線通信装置が、第1メッセージを第1無線アクセスポイントに送信する第1メッセージ送信ステップと、
     前記第1メッセージを受信した前記第1無線アクセスポイントが、前記第1無線アクセスポイントを示す第1アクセスポイント情報を含む第2メッセージをサーバに送信する第2メッセージ送信ステップと、
     前記第1無線アクセスポイントと同一又は異なる第2無線アクセスポイントと無線接続認証が既に完了している第2無線通信装置が、第3メッセージを前記第2無線アクセスポイントに送信する第3メッセージ送信ステップと、
     前記第3メッセージを受信した前記第2無線アクセスポイントが、前記第2無線アクセスポイントを示す第2アクセスポイント情報を含む第4メッセージを前記サーバに送信する第4メッセージ送信ステップと、
     前記サーバが、前記第1アクセスポイント情報で示される前記第1無線アクセスポイントと、前記第2アクセスポイント情報で示される前記第2無線アクセスポイントとを比較し、前記第1無線アクセスポイントと前記第2無線アクセスポイントとが同一の無線アクセスポイントである場合、当該同一の無線アクセスポイントを、前記第1無線通信装置の接続先の無線アクセスポイントである接続先アクセスポイントに決定する決定ステップと、
     前記接続先アクセスポイントと前記第1無線通信装置とが無線接続認証を行う認証ステップとを含む
     無線接続認証方法。
  5.  前記無線接続認証方法は、さらに、
     ユーザ操作に応じて、前記第2無線通信装置が前記第1無線通信装置に固有の第1コードを取得する取得ステップと、
     前記第2無線通信装置が、前記第1コードを前記サーバに送信する第1コード送信ステップと、
     前記サーバが、前記第1コードを用いて、前記第1無線通信装置と前記接続先アクセスポイントとの無線接続認証に用いられる第2コードを生成する第2コード生成ステップと、
     前記サーバが、前記第2コードを前記接続先アクセスポイントに送信する送信ステップと、
     前記第1無線通信装置が、前記第1コードと同一の第3コードを用いて第4コードを生成する第4コード生成ステップとを含み、
     前記認証ステップでは、前記第1無線通信装置及び前記接続先アクセスポイントが、前記第2コードと前記第4コードとが同一であるか否かに応じて、前記第1無線通信装置及び前記接続先アクセスポイントとの無線接続認証を行う
     請求項4記載の無線接続認証方法。
  6.  前記無線接続認証方法は、さらに、
     前記第1無線通信装置が第5コードを生成する生成ステップを含み、
     前記第1メッセージ及び前記第2メッセージの各々は、さらに、前記第5コードを含み、
     前記第2コード生成ステップでは、前記第1コード及び前記第5コードを用いて前記第2コードを生成し、
     前記第4コード生成ステップでは、前記第3コード及び前記第5コードを用いて前記第4コードを生成する
     請求項5記載の無線接続認証方法。
  7.  前記第3メッセージ送信ステップは、前記第1メッセージ送信ステップの後に行われる
     請求項4~6のいずれか1項に記載の無線接続認証方法。
  8.  前記無線接続認証方法は、さらに、
     前記第1メッセージ送信ステップの後に、前記第1無線通信装置が、無線信号を送信する無線信号送信ステップを含み、
     前記第3メッセージ送信ステップでは、前記第2無線通信装置が前記無線信号を受信した場合に、前記第2無線通信装置が、前記第3メッセージを前記第2無線アクセスポイントに送信する
     請求項7記載の無線接続認証方法。
  9.  前記第1メッセージ送信ステップは、前記第3メッセージ送信ステップの後に行われる
     請求項4~6のいずれか1項に記載の無線接続認証方法。
  10.  第1無線通信装置と無線アクセスポイントとの通信を確立するための無線接続認証を行うサーバであって、
     前記第1無線通信装置から送信された第1メッセージに従い第1無線アクセスポイントが送信した、前記第1無線アクセスポイントを示す第1アクセスポイント情報を含む第2メッセージを受信する第1受信部と、
     前記第1無線アクセスポイントと同一又は異なる第2無線アクセスポイントと既に通信が確立している第2無線通信装置から送信された第3メッセージに従い、前記第2無線アクセスポイントが送信した、前記第2無線アクセスポイントを示す第2アクセスポイント情報を含む第4メッセージを受信する第2受信部と、
     前記第1アクセスポイント情報で示される前記第1無線アクセスポイントと、前記第2アクセスポイント情報で示される前記第2無線アクセスポイントとを比較し、前記第1無線アクセスポイントと前記第2無線アクセスポイントとが同一の無線アクセスポイントである場合、当該同一の無線アクセスポイントを、前記第1無線通信装置の接続先の無線アクセスポイントである接続先アクセスポイントに決定する決定部と、
     前記接続先アクセスポイントと前記第1無線通信装置との無線接続認証を行うための処理を行う認証処理部とを備える
     サーバ。
  11.  請求項1記載の無線接続認証方法をコンピュータに実行させるための
     プログラム。
PCT/JP2014/002579 2013-05-22 2014-05-16 無線接続認証方法及びサーバ Ceased WO2014188686A1 (ja)

Priority Applications (3)

Application Number Priority Date Filing Date Title
US14/415,361 US9832640B2 (en) 2013-05-22 2014-05-16 Wireless connection authentication method and server
CN201480001902.5A CN104488302B (zh) 2013-05-22 2014-05-16 无线连接认证方法以及服务器
JP2014547212A JP6244310B2 (ja) 2013-05-22 2014-05-16 無線接続認証方法及びサーバ

Applications Claiming Priority (2)

Application Number Priority Date Filing Date Title
JP2013107711 2013-05-22
JP2013-107711 2013-05-22

Publications (1)

Publication Number Publication Date
WO2014188686A1 true WO2014188686A1 (ja) 2014-11-27

Family

ID=51933254

Family Applications (1)

Application Number Title Priority Date Filing Date
PCT/JP2014/002579 Ceased WO2014188686A1 (ja) 2013-05-22 2014-05-16 無線接続認証方法及びサーバ

Country Status (4)

Country Link
US (1) US9832640B2 (ja)
JP (1) JP6244310B2 (ja)
CN (1) CN104488302B (ja)
WO (1) WO2014188686A1 (ja)

Cited By (1)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
WO2020059584A1 (ja) * 2018-09-18 2020-03-26 パナソニックIpマネジメント株式会社 制御方法

Families Citing this family (9)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
JP6390126B2 (ja) * 2014-03-14 2018-09-19 株式会社リコー 情報処理システム、情報処理装置、情報処理方法、及びプログラム
US10466914B2 (en) * 2015-08-31 2019-11-05 Pure Storage, Inc. Verifying authorized access in a dispersed storage network
WO2017051937A1 (ko) * 2015-09-22 2017-03-30 (주) 이스트몹 P2p 파일 전송 시스템, 방법 및 프로그램
US10320766B2 (en) * 2015-11-17 2019-06-11 Google Llc Wireless network access
CN105979567B (zh) * 2016-05-13 2017-07-28 上海连尚网络科技有限公司 确定无线接入点的接入信息的方法及设备、系统
CN105933905B (zh) * 2016-07-11 2017-12-22 上海掌门科技有限公司 一种实现无线接入点连接认证的方法与设备
CN107995154A (zh) * 2016-10-26 2018-05-04 九阳股份有限公司 一种智能家电配网安全控制方法
CN106789462B (zh) * 2016-12-15 2021-10-08 九阳股份有限公司 一种智能家电入网安全控制方法
JP2025005665A (ja) * 2023-06-28 2025-01-17 キヤノン株式会社 通信システムおよび情報処理装置

Citations (3)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
JP2009253380A (ja) * 2008-04-01 2009-10-29 Canon Inc ユーザ認証方法、無線通信装置、基地局、及びアカウント管理装置
JP2010056916A (ja) * 2008-08-28 2010-03-11 Canon Inc 通信装置、通信装置の制御方法、プログラム
JP2012186516A (ja) * 2011-03-03 2012-09-27 Silex Technology Inc 無線lan機器設定システム

Family Cites Families (25)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
EP1398934B1 (en) * 2002-09-16 2008-01-02 Telefonaktiebolaget LM Ericsson (publ) Secure access to a subscription module
US8532304B2 (en) * 2005-04-04 2013-09-10 Nokia Corporation Administration of wireless local area networks
CN1875908A (zh) * 2005-06-08 2006-12-13 上海雷硕医疗器械有限公司 一种防止儿童误服药物的药品容器
TW200729892A (en) * 2005-11-16 2007-08-01 Nokia Corp System and method for establishing bearer-independent and secure connections
JP4929040B2 (ja) * 2007-05-10 2012-05-09 キヤノン株式会社 通信装置及び通信方法
CA2692083C (en) * 2007-06-26 2017-06-06 G3-Vision Limited Authentication system and method
JP4613969B2 (ja) * 2008-03-03 2011-01-19 ソニー株式会社 通信装置、及び通信方法
US8625552B2 (en) * 2008-12-31 2014-01-07 Microsoft Corporation Wireless provisioning a device for a network using a soft access point
KR101015665B1 (ko) * 2009-03-16 2011-02-22 삼성전자주식회사 이동 통신 단말과 액세스 포인트 간에 연결 방법 및 시스템
JP2010219754A (ja) * 2009-03-16 2010-09-30 Kddi Corp 無線通信システム、端末、アクセスポイント、アクセス権付与方法
JP2011061574A (ja) 2009-09-11 2011-03-24 Brother Industries Ltd 無線通信装置と無線通信システム
KR20130082073A (ko) 2010-05-05 2013-07-18 에스엠에스씨 홀딩스 에스에이알엘 Wi-fi 설정 및 구성을 위한 방법들 및 시스템들
JP5135445B2 (ja) * 2011-01-11 2013-02-06 株式会社バッファロー 無線lanシステム、通信装置、設定情報を共有する方法
JP6154098B2 (ja) 2011-03-08 2017-06-28 ソニー株式会社 無線通信装置、無線通信方法、及び無線通信システム
US9167508B2 (en) 2011-03-08 2015-10-20 Sony Corporation Wireless communication apparatus, wireless communication method, and wireless communication system for providing improved wireless communication
JP5647964B2 (ja) 2011-09-29 2015-01-07 Kddi株式会社 親の無線端末に従属する子の無線端末のアクセスを規制する無線ルータ、プログラム及びアクセス方法
WO2013114434A1 (ja) 2012-01-31 2013-08-08 パナソニック株式会社 端末装置、無線ネットワークシステム、及び、アクセスポイントに端末装置を接続する方法
US9143402B2 (en) * 2012-02-24 2015-09-22 Qualcomm Incorporated Sensor based configuration and control of network devices
CN104247554A (zh) * 2012-03-28 2014-12-24 索尼公司 信息处理装置、信息处理方法以及程序
JP5963528B2 (ja) 2012-05-07 2016-08-03 キヤノン株式会社 通信装置およびその制御方法
JP6009242B2 (ja) 2012-06-26 2016-10-19 Kddi株式会社 ユーザ所有のアクセスポイントに第三者の無線端末を接続させる認証方法、アクセスポイント及びプログラム
WO2014144601A1 (en) * 2013-03-15 2014-09-18 Master Lock Company Networked security system
US9167427B2 (en) * 2013-03-15 2015-10-20 Alcatel Lucent Method of providing user equipment with access to a network and a network configured to provide access to the user equipment
JP5639680B2 (ja) 2013-04-05 2014-12-10 任天堂株式会社 情報処理システム、情報処理装置、および情報処理プログラム
US20140328334A1 (en) * 2013-05-03 2014-11-06 Gainspan Corporation Provisioning a wireless device for secure communication using an access point designed with push-button mode of wps (wi-fi protected setup)

Patent Citations (3)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
JP2009253380A (ja) * 2008-04-01 2009-10-29 Canon Inc ユーザ認証方法、無線通信装置、基地局、及びアカウント管理装置
JP2010056916A (ja) * 2008-08-28 2010-03-11 Canon Inc 通信装置、通信装置の制御方法、プログラム
JP2012186516A (ja) * 2011-03-03 2012-09-27 Silex Technology Inc 無線lan機器設定システム

Cited By (3)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
WO2020059584A1 (ja) * 2018-09-18 2020-03-26 パナソニックIpマネジメント株式会社 制御方法
KR20210058743A (ko) * 2018-09-18 2021-05-24 파나소닉 아이피 매니지먼트 가부시키가이샤 제어 방법
KR102765556B1 (ko) 2018-09-18 2025-02-07 파나소닉 아이피 매니지먼트 가부시키가이샤 제어 방법

Also Published As

Publication number Publication date
CN104488302A (zh) 2015-04-01
JPWO2014188686A1 (ja) 2017-02-23
CN104488302B (zh) 2018-07-17
US20150172923A1 (en) 2015-06-18
JP6244310B2 (ja) 2017-12-06
US9832640B2 (en) 2017-11-28

Similar Documents

Publication Publication Date Title
JP6244310B2 (ja) 無線接続認証方法及びサーバ
US10976971B2 (en) Establishing wireless connection, by using terminal device, after determining which of external device or terminal device that communication device is to establish connection
JP5524157B2 (ja) プローブを使用する2つの装置間のセキュアなワイヤレスリンク
KR102060547B1 (ko) 무선 통신 시스템에서 무선 기기 등록 방법 및 장치
JP5844004B2 (ja) モバイルデバイスを使用して、別のデバイスのワイヤレスネットワークへの接続を可能にすること
EP2963959B1 (en) Method, configuration device, and wireless device for establishing connection between devices
JP5736987B2 (ja) 無線通信装置
JP2017046337A (ja) 無線接続を自動的に確立する方法、同方法を用いるモノのインターネット用のゲートウェイ装置及びクライアント装置
CN112205013B (zh) 用于无线通信切换的设备
JP6866191B2 (ja) 通信装置、通信制御方法およびプログラム
US9538375B2 (en) Method for configuring wireless connection settings, wireless communications apparatus, and display method
WO2014086252A1 (zh) 关联设备的方法、装置及系统
JP7394784B2 (ja) 他のデバイスとのワイヤレス通信用のデバイス
EP2993933A1 (en) Wireless terminal configuration method, apparatus and wireless terminal
JP2017163244A (ja) 情報処理システム、情報処理装置、情報処理方法、情報処理プログラム
JP2021158494A (ja) 通信システム、電子デバイス、およびプログラム
JP5659046B2 (ja) 無線通信端末および無線通信方法
JP2018033004A (ja) 情報処理装置、その制御方法、及びプログラム
JP2018007148A (ja) 無線通信システムおよび無線通信装置
JP2021013073A (ja) 通信装置と通信装置のためのコンピュータプログラム
JP2017183890A (ja) 通信システム、通信装置及び通信方法
US20190182668A1 (en) Information processing apparatus, method of controlling the same, and program
JP5791409B2 (ja) 無線通信接続方法及びアクセスポイント
JP2018026722A (ja) 通信装置、通信方法、及びプログラム
JP5738790B2 (ja) 無線通信端末、無線通信システム、無線セットアップ方法、およびプログラム

Legal Events

Date Code Title Description
ENP Entry into the national phase

Ref document number: 2014547212

Country of ref document: JP

Kind code of ref document: A

121 Ep: the epo has been informed by wipo that ep was designated in this application

Ref document number: 14800800

Country of ref document: EP

Kind code of ref document: A1

WWE Wipo information: entry into national phase

Ref document number: 14415361

Country of ref document: US

NENP Non-entry into the national phase

Ref country code: DE

122 Ep: pct application non-entry in european phase

Ref document number: 14800800

Country of ref document: EP

Kind code of ref document: A1