安全断言标记语言SAML是让互相信赖的双方可以交换安全相关信息的一个XML架构,它定义了不同系统之间安全服务交换认证和授权信息的机制,单点登录技术SSO是实现集成身份认证和授权服务的有效方法,通过对传统的SSO分析,提出一种基于SAML、利用PKI/PMI的单点登录企业级的应用系统,有效解决跨域系统和异构应用平台的一次认证、全程访问的安全信息交换;成功在“金税三期”资源整合中界面整合及门户项目得到应用。关键词: 安全断言标记语言;单点登录;安全服务;认证;授权Abstract: The Security Assertion Markup Language (SAML) is an XML framework forexchanging security information between reliantly parties, it defines a mechanism for exchanging authentication and authorization information among different systems, Single Sign On (SSO) is an effective method which implement Integrated authentication and authorization。Base on analyze traditional SSO ,this paper discussed an effective application system using SAML and PKI/PMI technology , which resolved Security information exchange among heterogeneous system through once authentication realize full access. This technology was used successful in the project of “third of CTAIS”.Key words: SAML;SSO;Web Services;Authentication;Authorization