The invention discloses a 
distributed security storage 
system, pertains to the technical filed of computer storage and aims at overcoming the problems of the heavy burden of a security manager and complex user authority management in the current security storage 
system based on a 
certificate. The storage 
system of the invention consists of an application 
client connected to a network, a storage device, a security and strategy manager and a 
metadata server; the security and strategy manager stores and manages the 
access control entry, 
access control strategy and rule of the whole system and carries out access strategy control and 
authority control over the storage device according to the 
access control entry, access control strategy and rule of the whole system, including the changes of the priority and inheritance rules of the access control entry and adding and deletion of the access control entry. The storage system of the invention distributes centralized 
authorization to storage nodes, avoids the performance 
bottle neck of the security manager, solves the problem of the complex user authority management, combines identification management and access control, eliminates access control redundancy and security holes and is applicable to establishing a large-scale security storage system with high performance.