The invention discloses a
distributed security storage
system, pertains to the technical filed of computer storage and aims at overcoming the problems of the heavy burden of a security manager and complex user authority management in the current security storage
system based on a
certificate. The storage
system of the invention consists of an application
client connected to a network, a storage device, a security and strategy manager and a
metadata server; the security and strategy manager stores and manages the
access control entry,
access control strategy and rule of the whole system and carries out access strategy control and
authority control over the storage device according to the
access control entry, access control strategy and rule of the whole system, including the changes of the priority and inheritance rules of the access control entry and adding and deletion of the access control entry. The storage system of the invention distributes centralized
authorization to storage nodes, avoids the performance
bottle neck of the security manager, solves the problem of the complex user authority management, combines identification management and access control, eliminates access control redundancy and security holes and is applicable to establishing a large-scale security storage system with high performance.