| This paper elaberately analyzed and researched two critical principle ofRole-based Access Control(RBAC) and Lightweight Directory Access Protocol(LDAP), have consideration of the virtue of RBAC's implementation in theenvironment of LDAP, so we can do the user access control by the concept of RBAC,use the LDAP to manage the user data, take advantage of the virtue of LDAP, resolvesome defects of managing the user data by traditional datebase and the managementproblem of organization, department and user by large enterprises, reduce thecomplexity of authentication, make the application system ofE-Government/E-Commerce to adept different organization and department andimplement the efficiency and safety of the user management.This object implemented a better unified user management component, suppliedapplication programme interfere, resolved the large waste of software's repetingdevelopment developing a unique user administration system for different applicationsystem. At the same time, the component is universal, safe, and extensible, and it canflexiblely adept different need of many enterprises. Finally, we have formed a betterframework for software development in the process of the development of thecomponent.At the end of this paper, we analyzed some defects of this object, and suppliedthe improving direction in the future. |