Access control based on the password is researched, a secure user authentication model with DES, SHA- 512 and Diffe- Hellman key exchange protocol is proposed. This model not only prevents MiM attack, replay attack,guess password attack and denial of service attack, but also provides the perfect forward secrecy. A C/S - based prototype is developed with hook technology.