结合网格发展的需要,分析了当前广泛采用的Kerberos 身份认证机制,研究了 不同网格环境下GSI 方案和KX.509 方案。在此基础上,借鉴KX.509 的代理思想,在Globus环境下提出了一种采用web 登陆模块构建的网格身份认证模型,为校园网格用户提供透明的证书生成、使用和管理。在用户注册和认证过程中,web 登陆模块自动为用户产生数字代理证书,使用户不需拥有自己的数字证书。 关键词:网格安全;认证;Kerberos ;KX.509 Abstract. Integrating the needs of grid development, analyzed current broadly adopted Kerberos authentication mechanism, and researched GSI and KX.509 in different grid environment. On these basis, drawing the proxy idea of KX.509, give a grid authentication model which adopt weblogin module in the Globus environment. For the campus grid user provides the transparent certificate creation, employment and management. In the process of registration and authentication, weblogin automatically create digital proxy certificate for users, and users needn’t have their own digital certificate. Key words: grid security; authentication; Kerberos; KX.509