If I understood you question, to secure an MPLS connectivity you have some options.
1) You can encrypt you PE-CE link using IP-SEC 3DES and the service provider using VRF-Aware IPSEC can put your incoming interface into the right VRF for you as per the authentication parameters.
2) Or else you can secure your end-to-end link using IP-SEC just like you do with IP, wusing 3DES, without intervention from your service provider.
If that is what you were asking.
HTH-Cheers,
Swaroop