对传统虚拟专用网的概念进行扩展,提出并建立了分布式虚拟专用网的模型,解决了传统虚拟专用网系统内部无法防止的搭线窃听问题。对分布式虚拟专用网的性能改进作了定量分析,分析结果显示其可以大幅度提高系统的并行性,且单个节点存储容量从O(n2)下降到O(),实现增长线性化,并给出一个系统实现,测试结果表明可以显著改善系统的安全性和提高效率。关 键 词 虚拟专用网; 分布式虚拟专用网; IP安全性; 安全策略数据库; 安全关联数据库Raise the concept of distributed VPN and create the system model, which extend the concept of classical VPN. From the as aspects of security, it overcome the classical VPN’s disadvantages of failing to protect the internal communication of LANs. The result of DVPN's performance analyzing indicates that it can enhance the parallelity of the system,reduce the storage requirement from complexity O(2n) to O() and make the database grow linearly. As well,give a system implementation, which proves that it can improve the security and efficiency of the system.