As it seems implementing security in JEE platform would be a tedious task.
but consider this:
1-if you want security at EJB level, learn how to integrate security with EJB
2-if you need security at servlet level, read your AppServer manual. but instead