The research of access control model is a topic of information security area.There are many access control models in existing literatures
but they process the access requests only depending on existing conditions by themselves.Therefore they are not able to meet the need that authorization process must interact with users and that user's promises of the future actions are authorization conditions under electronic commerce environment.A promise-assurance-based access control model (PABAC) is presented to achieve the above access control need.Its architecture
promise assurance mechanism
separation of duties of authorization and access control are discussed.The experimental results express its validity.