本文提出了一种集成功能权限和数据权限的通用的权限管理模型,该模型在主要对角色授权的基础上加入了对用户直接授权和屏蔽部分角色权限的机制,丰富了传统模型对功能权限的控制,并且增加了数据权限的管理,有效地解决了各种管理系统中复杂的访问控制问题。关键词:RBAC,功能权限,数据权限A Universal Scheme of Authority Management Model LIN Wei-ju LIU Lie-gen ZHANGYu (Research Institution of Computer Application, South China University of Technology, Guangzhou, 510641) Abstract:In this paper, a universal scheme of authority management model integrates function permission and data permission is put forward. The model, manily based on the role authorization, has added the mechanism of user authorization and shielding part of authorization. It enriches function permission and adds the management of data permission,as well as solves the complex access control problems of a variety of management systems effectively.Key words:RBAC,function permission,data permission