The invention discloses an attribute-based 
access control model and a cross domain 
access method thereof. The attribute-based 
access control model comprises a first management domain and a second management domain, and is characterized by comprising 
certificate servers and attribute management servers. The cross domain 
access method of the 
system comprises the following steps: the 
certificate servers are respectively used for awarding a 
server certificate for the first management domain and the second management domain; a user downloads an attribute certificate to a local disk for storage by 
logging on the first management domain; the user submits the attribute certificate to the second management domain; a second 
access control server verifies the attribute certificate; and the second access control 
server extracts an attribute value to judge the operation validity of the user. The attribute-based access control model and the cross domain 
access method thereof of the invention have the obvious advantages that the role of the user and the management domains can be considered as a single attribute of the user, the efficiency problem of user-role-authority valuation under the condition of complex role in a role-based access control (RBAC) model can be effectively solved, and the corresponding access control method is provided for an anonymous user in an open network environment.