Abstract The VPN service management architecture is proposed based on the logical layer architecture of the TMN and the function of the subsystem in the architecture is analyzed. Based on this, the management information modei of the VPN service management is presented and the mapping relationship between this modei and ATM network/network element layer managed object classes is also given. The security function of the system is discussed in detail.