The invention relates to an
access control method of
network storage equipment, belonging to a
computer network storage
system. The invention solves the problem that the prior
access control method maintains and manages one centralized
access control list, thereby forming the performance
bottleneck and influencing the performance and the expandability of the storage
system. In the invention, the access control method comprises the steps of object establishment and object operation. The
network storage equipment stores
data objects and
directory objects needed by users, each of the data objectsand the
directory objects comprises an attribute part and a data part, and each attribute part comprises an
access control list. The invention uses each
access control list as a security attribute ofeach data object to be stored together with the data, defines the inherited rules of each
access control list and the priority of each access control item, improves the flexibility of
data access control, positions the corresponding access control
list while reading the data to be operated by users, realizes the distributed access control, greatly reduces the access control cost of a distributedstorage
system, and improves the expandability of the system.