The application discloses a kind of based on distributed account book's IoT
equipment use benefit right management method and
system, and store the root block containing
block number,
internet of things equipment identification, time stamp, authority set, tenant public key and tenant signature by tenant node generation;In response to lease request, generate the first-level block containing
block number, previous block hash value, time stamp, lease period, lease authority set, tenant public key and tenant signature, or by tenant in response to share request Generation of the following block containing
block number, predecessor hash value, time stamp, share start end time, share authority set, sharer public key and tenant signature;The user node of request access equipment constructs authority token, which contains complete
authorization chain from root block to target block and signed command message;
Internet of things equipment receives token and executes
hash chain verification, public key-signature chain
verification and
business rule verification, executes command after passing through.This way, the access permission information of the application does not have to be stored in resource party any more, but is verified by resource party with request when user access, so that user permission information and resource party are decoupled.