In this article , we perform a tri - layer security mechanism ; we improve the form authentication of asp . net in two places ; we also perform a new dynamic authentication based on two factor ; then we perform a new way to send the credential through the soap header ; we solve the problem about the key creation and the key storage and the transmission of the encrypted message ; after analyzing and discussing the soap protocol , we put forward a safely custom authentication through combining the digest authentication and soap protocol and credential 在web服务安全方面提出了一些新看法,解决了一些新问题: 1 )提出了基于角色的三层安全机制; 2 )对asp , net的表单验证技术提出了两处新的改进: 3 )提出一种动态的双因素口令认证方法,即在单因素(固定口令)认证基础上结合第二个物理认证因素,以使认证的确定性按指数递增。在此,本文提出了第二种认证因素?信任凭证。