I don't know why most of Iranian IT professionals insists to solve their problems with the most abnormal way that ever exists ;)
If you are making your webservice secure, there is a perfect technology called WSIT for JAX-WS, and you can send any kind of token, secure or not secure, encrypted, signed or not signed, embedded with your webservice.
java.sun.com/.../index.html
If WSIT is not the solution, please explain the problem and the reason you're gonna do that.