In SESAME, the user is first authenticated to an authentication server and receives a token. The token is then presented to a privilege attribute server as proof of identity to gain a(n) __________.
It is used to encode authorization information. It contains security metadata, policy information, profile, additional credential information and memberships.