The application of single-sign-on is a technology which aims to manage the access control of the internal systems of enterprises. The traditional single-sign-on models cannot simultaneously meet the requirements in implementation, manageability, system pressure, and security. In this paper, based on the traditional models of gateway and broker, we propose an improved model that integrates the advantages of these two models. Both theoretical analysis and experimental results indicate that our proposed model have good performances in implementation, manageability, system pressure, and security.