IP Library Granted Patent US 9,467,323
Granted Patent B2
US 9,467,323 · App. 14/704,041 · Granted Oct 11, 2016

Communication device and a control method therefor that perform authentication using digital certificates

Inventor: Eiji Kasai (Matsumoto, JP)
Assignee: Seiko Epson Corporation
H04L29/06G06F3/1204G06F3/1222G06F3/1236G06F3/1238G06F3/1296G06F3/1297H04L9/3268H04L63/0823H04L67/42
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 9,467,323
App. No.
14/704,041
Granted
Oct 11, 2016
Kind
B2
Abstract

A communication device having time information that may not be correct can efficiently and accurately authenticate a server certificate. The communication unit of a printer processes server authentication that inspects a server certificate when connecting to an external network. Server authentication includes a first authentication that verifies the validity period of the server certificate based on status information and time information stored by the communication unit. The communication unit cuts the connection to the external network if the time information stored by the communication unit is after the validity period (the validity period is clearly expired). The first authentication reliably succeeds if the communication unit has the correct time information and a valid server certificate. If the time information is before the validity period, the time information may be old, and processing proceeds based on the status information.

Claims (82)

1. A control method of a communication device that performs server authentication and inspects a server certificate, which is a digital certificate with a set validity period, when connecting to a network, the control method comprising:

the communication device storing time information and status information, which indicates whether the time information is a provisional time or verified time;

doing a first authentication that determines during server authentication if the time indicated by the time information is before the start time of the validity period, during the validity period, or after the validity period ends;

stopping connecting to the network using the server certificate if the first authentication determines that the time indicated by the time information is after the validity period ends;

attempting a second authentication that inspects other authentication information included in the server certificate if the first authentication determines that the time indicated by the time information is during the validity period;

executing a preset process based on the status information if the first authentication determines that the time indicated by the time information is before the start time of the validity period and the status information is set to provisional time; and

stopping connection to the network if the first authentication determines that the time indicated by the time information is before the start time of the validity period and the status information is set to verified time.

2. The control method of a communication device described in claim 1 , wherein:

the preset process is a provisional setting process that sets the time information to information indicating a preset time in the validity period; and

attempts the second authentication after the provisional setting process.

3. The control method of a communication device described in claim 1 , further comprising:

setting the time information to a previously stored startup time; and

setting the status information to provisional time;

before the first authentication.

4. The control method of a communication device described in claim 3 , further comprising:

when connection to the network using the server certificate is enabled,

executing a time updating process that updates the time information to a current time acquired through the network, and

updating the startup time to the time information if the status information is set to verified time and the time difference between the time information and the startup time is greater than or equal to a preset threshold.

5. The control method of a communication device described in claim 1 , further comprising:

when connection to the network using the server certificate is enabled,

executing a time updating process that updates the time information to a current time acquired through the network,

changing the status information to verified time if the status information is set to provisional time, and

cutting the network connection and attempting the first authentication using the updated time information.

6. The control method of a communication device described in claim 1 , further comprising:

updating the time information to the received current time when information indicating the current time is received without accessing the network; and

changing the status information to verified time if the status information is set to provisional time.

7. A communication device comprising:

a processor that manages time information and status information, which indicates whether the time information is a provisional time or verified time;

the processor processing server authentication to inspect a server certificate, which is a digital certificate with a set validity period, when connecting to a network;

the processor performing a first authentication that determines during server authentication if the time indicated by the time information is before the start time of the validity period, during the validity period, or after the validity period ends;

stopping connecting to the network using the server certificate if the first authentication determines that the time indicated by the time information is after the validity period ends;

attempting a second authentication that inspects other authentication information included in the server certificate if the first authentication determines that the time indicated by the time information is during the validity period;

executing a preset process based on the status information if the first authentication determines that the time indicated by the time information is before the start time of the validity period and the status information is set to provisional time; and

stopping connection to the network if the first authentication determines that the time indicated by the time information is before the start time of the validity period and the status information is set to verified time.

8. The communication device described in claim 7 , wherein:

the preset process is a provisional setting process that provisionally sets the time information to information indicating a preset time in the validity period; and

the processor attempts the second authentication after the provisional setting process.

9. The communication device described in claim 7 , further comprising:

a storage that stores a preset startup time;

the processor executing a process of setting the time information to the startup time read from the storage, and a process of setting the status information to provisional time, before the first authentication.

10. The communication device described in claim 9 , wherein:

when connection to the network using the server certificate is enabled, the processor

executes a time updating process of updating the time information to a current time acquired through the network, and

executes a process of updating the startup time to the time information if the status information is set to verified time and the time difference between the time information and the startup time is greater than or equal to a preset threshold.

11. The communication device described in claim 7 , wherein:

when connection to the network using the server certificate is enabled, the processor

executes a time updating process of updating the time information to a current time acquired through the network, and

executes a process of changing the status information to verified time if the status information is set to provisional time; and

the processor executes a process of cutting the network connection and attempting the first authentication using the updated time information when the status information is changed to verified time.

12. The communication device described in claim 7 , wherein:

the processor executes a process of updating the time information to the received current time when information indicating the current time is received without accessing the network, and

changing the status information to verified time if the status information is set to provisional time.

13. A printer comprising:

a processor that manages time information and status information, which indicates whether the time information is a provisional time or verified time, and processes server authentication to inspect a server certificate, which is a digital certificate with a set validity period, when connecting to a network;

a print unit that prints on print media based on data received through the processor;

the processor performing a first authentication that determines during server authentication if the time indicated by the time information is before the start time of the validity period, during the validity period, or after the validity period ends;

stopping connecting to the network using the server certificate if the first authentication determines that the time indicated by the time information is after the validity period ends;

attempting a second authentication that inspects other authentication information included in the server certificate if the first authentication determines that the time indicated by the time information is during the validity period;

executing a preset process based on the status information if the first authentication determines that the time indicated by the time information is before the start time of the validity period and the status information is set to provisional time; and

stopping connection to the network if the first authentication determines that the time indicated by the time information is before the start time of the validity period and the status information is set to verified time.

14. The printer described in claim 13 , wherein:

the preset process is a provisional setting process that provisionally sets the time information to information indicating a preset time in the validity period; and

the processor attempts the second authentication after the provisional setting process.

15. The printer described in claim 13 , further comprising:

a storage that stores a preset startup time;

the processor executing a process of setting the time information to the startup time read from the storage, and a process of setting the status information to provisional time, before the first authentication.

16. The printer described in claim 13 , wherein:

when connection to the network using the server certificate is enabled,

the processor executes a time updating process of updating the time information to a current time acquired through the network, and

executes a process of updating the startup time to the time information if the status information is set to verified time and the time difference between the time information and the startup time is greater than or equal to a preset threshold.

17. The printer described in claim 13 , wherein:

when connection to the network using the server certificate is enabled,

the processor executes a time updating process of updating the time information to a current time acquired through the network;

executes a process of changing the status information to verified time if the status information is set to provisional time; and

executes a process of cutting the network connection and attempting the first authentication using the updated time information when the status information is changed to verified time.

18. The printer described in claim 13 , wherein:

the processor executes a process of updating the time information to the received current time when information indicating the current time is received without accessing the network, and

changing the status information to verified time if the status information is set to provisional time.

19. The printer described in claim 13 , wherein:

the print unit that prints a message on the print medium indicating the network connection was interrupted when the connection is interrupted.

20. The printer described in claim 13 , wherein:

the print unit that when connected to the network, prints on the print medium based on print data received from a device on the network.

Assignments (1)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded May 5, 2015
From: KASAI, EIJI
To: SEIKO EPSON CORPORATION
Reel/Frame 035564/0125 →
Priority Claims (2)
JP 2014-103140 · May 19, 2014 · national
JP 2015-042099 · Mar 4, 2015 · national
Continuity (1)
Related Publication 20150334109A1 · Nov 19, 2015