A method for creating a proof of possession confirmation for inclusion by
an attribute certificate authority into an attribute certificate, the
attribute certificate for use by an end user. The method includes
receiving from the attribute certificate authority in response to a
request by the end user, a plurality of data fields corresponding to a
target system, the identity of the end user, and a proof of identity
possession by the end user. The method further includes preparing a data
structure corresponding to an authorization attribute of the attribute
certificate, the data structure including a target system name, the
identity of the end user, and the key identifier of the end user. Using a
private key associated with the target system, the method includes
signing the data structure resulting in a proof of possession
confirmation, and sending the proof of possession confirmation to the
attribute certificate authority for inclusion into the attribute
certificate.