本文在深入研究教育城域网建设的特点后,给出了一种基于 VPN 技术的教育城域网 建设的模式。文中从VPN 技术分析入手,总结出了VPN 在网区中的部署方式,并给出了 VPN 在教育城域网部署中的推荐模型。此外还把基于角色的访问控制(RBAC)模型引入到 VPN 教育城域网中,提出了保持角色互斥和最小权限的办法,并给出了基于RBAC 的具 体设计与实现办法。 关键词: 虚拟专用网、基于角色的访问控制、教育城域网、安全 Abstract:This paper has produced one kind the EduMAN pattern which constructs based on the VPN technology, after the research of EduMAN the characteristic ,.In the article starts from the VPN technology analysis, summarizes VPN in the net area deployment way, and has produced the recommendation deployment model in the VPN EduMAN. In addition the RBAC has also been introduced in the VPN EduMAN, proposed the maintenance of role incompatible and the smallest jurisdiction means, and the realization means has also been given. Keyword: VPN, RBAC, EduMAN,Security