1460739288-e24eb8e3-f711-40e9-a70d-29249556dbca

1. An output circuit comprising:
an output transistor an emitter of which is grounded, a base of which serves as an input node for a control current and a collector of which serves as an output node;
a base current supply section for supplying a base current to the output transistor according to an input signal; and
a base current control section for detecting an inter-terminal voltage between the collector and emitter of the output transistor to control a base current supplied from the base current supply section so as not to cause the inter-terminal voltage to fall to a value lower than a predetermined constant voltage, wherein the base current control section comprises a comparator having the inter-terminal voltage and the predetermined constant voltage as a differential input, and wherein the input signal separated from the predetermined constant voltage.
2. An output circuit according to claim 1, wherein
the base current control section further comprises an amplifier which amplifies a first control current obtained by splitting the base current supplied from the base current supply section according to the inter-terminal voltage to generate a second control current and, by splitting the second control current from the base current, controls the base current supplied to the input node.
3. An output circuit according to claim 1, wherein
the base current control section supplies a first control current obtained by splitting the base current supplied from the base current supply section according to the inter-terminal voltage to the output transistor as a collector current thereof to thereby control the base current supplied to the input node.
4. An output circuit according to claim 1, wherein
the base current control section splits a first control current obtained by splitting the base current supplied from the base current supply section according to the inter-terminal voltage into at least two currents and one of the two currents is amplified by an amplifier to generate a second control current and, by splitting the second control current from the base current and supplying the other current to the output transistor as a collector current thereof, controls the base current supplied to the input node.
5. An output circuit according to claim 1, wherein
the output transistor is an NPN transistor.
6. An output circuit according to claim 1, wherein
the comparator is a PNP transistor.
7. An output circuit according to claim 2 or 4, wherein
the amplifier is a current mirror circuit.
8. An output circuit according to claim 2 or 4, wherein
the amplifier uses a current amplification action of a transistor.
9. An output circuit comprising:
an NPN output transistor an emitter of which is connected to a first power supply potential, a base of which serves as an input node for a control current, and a collector of which serves as an output node;
a PNP output transistor an emitter of which is connected to a second power supply potential, a base of which serves as an input node for a control current and a collector of which serves as an output node in common to the PNP output transistor and the NPN output transistor;
a first base current supply section for supplying a base current to the NPN output transistor according to an input signal;
a first base current control section for detecting a first inter-terminal voltage between the collector and emitter of the NPN output transistor to control a base current supplied from the first base current supply section so as not to cause the first inter-terminal voltage to fall to a value lower than a first predetermined constant voltage;
a second base current supply section for supplying a base current to the PNP output transistor according to the input signal; and
a second base current control section for detecting a second inter-terminal voltage between the collector and emitter of the PNP output transistor to control a base current supplied from the second base current supply section so as not to cause the second inter-terminal voltage to fall to a value lower than a second predetermined constant voltage,
wherein the first base current control section includes a comparator having the first inter-terminal voltage and the first predetermined constant voltage as a different input, and
the second base current control section includes a comparator having the second inter-terminal voltage and the second predetermined constant voltage as a differential input.

The claims below are in addition to those above.
All refrences to claim(s) which appear below refer to the numbering after this setence.

1. In a computing environment, a method of binding a security artifact to a user’s account at a service provider, the method comprising:
determining a user’s identity;
generating a pseudonym for a security artifact, wherein the pseudonym is an identifier of the security artifact to the service provider that is unique to the service provider in that the pseudonym is not used to identify the security artifact to other service providers and in that it uniquely identifies the particular security artifact to the service provider even when the user has available a plurality of different security artifacts to authenticate to the same service provider to access a user account for the user; and
providing the pseudonym for the security artifact to the service provider, wherein the pseudonym for the security artifact is bound with a user account at the service provider for the user associated with the security artifact.
2. The method of claim 1, wherein generating a pseudonym for a security artifact comprises using a service provider identifier, the service provider identifier uniquely identifying a service provider, and a security artifact secret, the security artifact secret uniquely identifying the security artifact.
3. The method of claim 1, wherein generating a pseudonym for a security artifact comprises the security artifact generating the pseudonym and wherein providing the pseudonym for the security artifact to the service provider comprises the security artifact providing the pseudonym to the service provider as part of a binding protocol exchange.
4. The method of claim 1, wherein generating a pseudonym for a security artifact comprises randomly generating the pseudonym whereafter the pseudonym is associated with both the security artifact and the service provider.
5. The method of claim 1, wherein the pseudonym for the security artifact comprises a public key of an asymmetric key set.
6. The method of claim 1, wherein the acts of claim 1 are repeated with the same security artifact, but with a different service provider, resulting in generating a different pseudonym that is used by the same security artifact with the different service provider.
7. The method of claim 1, wherein the acts of claim 1 are repeated with a different security artifact, but with the same service provider, resulting in generating a different pseudonym that is used by the different security artifact with the same service provider, such that a user account is associated with a plurality of different security artifacts, any one or more of which may be used to access the user account.
8. The method of claim 1, wherein the security artifact comprises a portable hardware device including at least one of a USB dongle, smart chip on a card or a SIM card in mobile phone.
9. The method of claim 1, wherein the security artifact includes functionality for accepting second factor authentication including at least one of provisions for biometric validation or pin entry.
10. The method of claim 1, wherein the security artifact comprises a software module implemented on a computer system by storing computer readable instructions in one or more physical computer readable media and executing the computer readable instructions using one or more processors.
11. The method of claim 1 further comprising, using the security artifact to authenticate directly to the service provider upon access.
12. The method of claim 1 further comprising, using the security artifact to protect one or more ephemeral or long-lived security tokens that have been issued for one or multiple uses.
13. In a computing environment, a method of using a security artifact bound to a user account at a service provider, the method comprising:
receiving a security artifact challenge from a service provider;
accessing a unique identifier for the service provider;
using the unique identifier from the service provider and a unique secret for a security artifact, generating an asymmetric private key;
accessing a nonce;
signing the nonce with the asymmetric private key;
sending the signature on the nonce to the service provider, whereafter the service provider validates the signature on the nonce to authenticate the security artifact; and
accessing the service provider as a result of the service provider authenticating the security artifact
14. The method of claim 13, wherein sending the signature on the nonce to the service provider comprises sending the signature on the nonce to an application which forwards the signature to the service provider.
15. The method of claim 13, wherein the security artifact challenge is received as a result of an application sending an access request.
16. The method of claim 13, wherein the acts of claim 13 are repeated with the same security artifact, but with a different service provider, such that the same security artifact is used with different service providers.
17. The method of claim 13, wherein the acts of claim 13 are repeated with a different security artifact, but with the same service provider, such that a user account at the service provider is associated with a plurality of different security artifacts, any one or more of which may be used to access the user account.
18. The method of claim 13, wherein the security artifact comprises a portable hardware device including at least one of a USB dongle, smart chip on a card or a SIM card in mobile phone.
19. The method of claim 13, wherein the security artifact comprises a software module implemented on a computer system by storing computer readable instructions in one or more physical computer readable media and executing the computer readable instructions using one or more processors.
20. In a computing environment, a method of validating a user using a security artifact at a service provider, the method comprising
receiving a request from a security artifact for a site key;
in response to the request from the security artifact for a site key, returning a service provider unique identifier to the security artifact;
receiving from the security artifact a pseudonym from the security artifact, wherein the pseudonym is generated using the service provider unique identifier and a security artifact secret unique to the security artifact, wherein the pseudonym comprises a public key of an asymmetric key pair;
registering the pseudonym with a user account at a service provider;
receiving a request for access of to the user account from an application;
sending a message to the application indicating that authentication is required to service the request;
receiving a request from the application for authentication;
in response to receiving a request from the application for authentication, sending a security artifact challenge to the application, wherein the device challenge comprises the service provider unique identifier and a nonce;
receiving a security artifact response comprising the signature on a nonce generated using a private key generated using the service provider unique identifier and the security artifact secret unique to the security artifact; and
validating the security artifact response using the pseudonym.