: Web services over the Internet are widely used nowadays. The problem of secure access to Web-based systems is of great importance naturally. Compared with the existing models, the Action-Based Access Control (ABAC) model is more suitable to control the access on Web services. In this paper, the ABAC model is introduced. Then, the security architecture of ABAC for Web services is proposed. In the architecture, the Action server manages the action information, the Domain server determines the security rank of request resources, and the Resource server storing the resources with different security ranks responses requests from users. Finally, the cookie is extended with security properties.