Abstract:According to the requirement for authority management of web systems, the paper puts forward an extended authority access control model based on RBAC, adds resource management of web systems, and also the ability of the direct authority for users without by roles, then introduces the independent data design of the model, and the prototype with the form of components. The complex access control of these systems can be figured out in some web systems.