A distributed
information system authority control method comprises the following steps: setting four identity entities including a resource owner, a resource access authorizer, a resource access requester and a resource identity publisher, and endowing the resource owner with two capabilities: the first capability is a
resource management capability, the second capability is a
resource management capability, and the third capability is a
resource management capability; the first capability is the capability of providing resource access to the outside, the second capability is the capability of providing resource access to the outside, the first capability means that the resource owner can manage own
digital resources including adding, querying, updating and deleting the resources, the second capability means that the resource owner provides an access interface to the outside, and when a resource access requester accesses the required resources through the access interface, the resource access requester can access the required resources through the access interface. According to the resource
access method, the authorized resource can be accessed after permission
verification is passed, when a resource owner has a new resource, the resource owned by the resource owner needs to be registered to a resource access authorizer synchronously, and a resource access requester registers the identity of the resource owner to the resource access authorizer before requesting to access the resource.