| In the process of e-government and enterprise intranet information construction,there are too many applications, excursive management of users and permissions,complex problems in management and maintenance and so on, therefore establishing aResource Management and Authorization Service System based on PMI and achievingsystems unified management of users, resources and permissions is particularlyimportant.This paper first analyzes the research status of the PKI, PMI and access control athome and abroad, and study in depth principles and architecture of the PMI. Itintroduces traditional access control model, focuses on the next generation of accesscontrol model UCON model principles and core components, and analyzes the strengthsand weaknesses of the UCON model. On this basis, this paper has a overall design toResource Management and Authorization Service System, and has the detailed designand analysis to the system’s core subsystem and complied the management subsystem ofthe organization members, resource management subsystem, authorization managementsubsystems and data exchange module.After deployment and testing of these several subsystems, it deals with thedeficiencies of rights management in the practical application of traditionalauthorization management system, and adapts to the authorized managementmechanism of application system in the actual business. It improves the efficiency ofthe authorization management. |