A system and method grants security privilege in a communication system by
providing privilege test criteria data for a subscriber unit so that the
subscriber unit or some other entity can select among subscriber privilege
data based on the privilege test criteria data, so that only the necessary
privilege information is communicated between the relying party and the
subscriber unit of interest. A privilege data selector selects, for
example, among a plurality of attribute certificates associated with a
selected subscriber unit or among sets of privilege data within an
attribute certificate, the certificate (or certificates) that matches the
privileged test criteria data. This pre-selected certificate is then
communicated for use by the relying unit and verified that it meets the
test selected by the relying party unit.