Abstract:Single Sign-On (SSO) is an efficient and secure authentication solution for portal system. This paper analyses the architecture and authentication process of CAS. By extending the CAS, a mechanism of coarse-grained Role Based Access Control is added to CAS. This paper proposes a new model of CAS, which has a coarse-grained and loosely-coupled Role Based Access Control. The extended CAS cannot be used for authentication, but can also be used for authorization, which increases availability and heighters the security of the system.