Access Control Sandbox Model for Web Services Sun Ruijia, Ye Xiaoling, zhang Yingchao,Gao Lianjun (Nanjing University of Information Science& Technology, Nanjing 210044) 【Abstract】This paper proposed an access control sandbox model for Web Services. Rather than basing access on the traditional validation of a client’s identity, the model also takes the roles validation into account via extending the SOAP message by adding roles information to it .Further more, the model also proposed a kind of mechanism of Security Manager. This kind of mechanism makes the Web Services designer and maintainer can maintain the security of the Web Services access through a more low level and more flexible way. 【Key Words】 Web Services; access control; information security