本文对自主访问控制(DAC)、强制访问控制(MAC)和基于角色的访问控(RBAC)的模型进行了研究,分析了数据加密机制及在访问控制中的应用,提出了一种基于角色和加密技术的访问控制系统设计方案,该方案在工程中得到了实现。 关键词:角色; RBAC;访问控制;加密 Abstract: Firstly this paper introduces three access control mechanisms: discretionary access control(DAC), mandatory access control(MAC), role–based access control(RBAC), and emphatically analyses the RBAC technology. Then analyses the data encryption scheme and its application in access control. Finally a design scheme based on encryption technology and RBAC is presented, the scheme has been implemented in a project. Key words: Role;RBAC;access control;encryption