Resource Public Key Infrastructure (RPKI) is a security system for internet routing. It lets holders of certified IP address space publish cryptographically signed records, called route origin authorizations (ROAs), naming the autonomous system numbers (ASNs) authorized to originate their prefixes. Holding an ASN does not by itself authorize a network to announce anyone’s addresses; that authorization comes from the address holder. Other networks can check routes they receive through the Border Gateway Protocol (BGP) against those records and reject announcements that don’t match. RPKI is operated by the five regional internet registries, and adoption has grown steadily among major networks.
At a glance
- IP address holders publish signed route origin authorizations (ROAs) naming the ASNs allowed to originate each prefix.
- Networks that perform route origin validation compare BGP announcements against ROAs and can drop invalid ones.
- It helps against misconfigurations and many origin hijacks, but does not on its own verify the full route path.
- Protection depends on both sides: holders publishing accurate ROAs and networks filtering invalid routes.
- The regional internet registries run the trust anchors and provide tools to create ROAs.
What problem it solves
BGP, the protocol networks use to tell each other which addresses they can reach, was built on trust. If a network announces a block of addresses, many others will believe it and send traffic there, whether or not that network holds the block. Configuration mistakes and deliberate hijacks have repeatedly pulled traffic for major services to the wrong place, causing outages and, in some cases, interception.
RPKI gives the rest of the internet a way to check. The legitimate holder signs a statement that only specific networks may originate its addresses. A network receiving a route can look up that statement and, if the origin doesn’t match, treat the route as invalid. Wrong announcements from the wrong origin can then be filtered before they spread.
How it works
Certificates. Each regional internet registry acts as a trust anchor and issues resource certificates to its members, binding them to the address blocks and AS numbers they hold. This uses the same cryptographic ideas as other public key infrastructure (PKI), applied to number resources rather than names.
ROAs. Using a registry’s hosted service or their own delegated setup, address holders create route origin authorizations. A ROA lists a prefix, the autonomous system allowed to originate it, and a maximum prefix length.
Validation. Networks run validator software that downloads and checks the signed records from all registries and builds a list of valid origin-prefix pairs. Routers use that list to mark each BGP route as valid, invalid or not found (no ROA exists).
Filtering. Each network decides what to do with invalid routes. Many large transit providers and internet exchange point route servers now drop them. Routes with no ROA are typically still accepted.
Path validation. Route origin validation checks only who originates a route. Additional mechanisms aimed at validating the path a route takes are being developed and deployed, but are less widely used.
If you buy internet transit and want to confirm a provider’s routing security practices, see our IP Transit solution page.
When it matters for buyers
- Holding your own address space. If you announce provider-independent addresses, publishing ROAs helps protect them from being hijacked or misrouted.
- Choosing transit or peering partners. Providers that validate and drop invalid routes reduce the chance you receive or forward bad routes.
- Changing providers or adding one. Your ROAs must name the ASN of each network that will originate your addresses, or validating networks may drop your routes.
- Customer and regulatory questions. Routing security is increasingly part of security questionnaires and government guidance in some countries.
Questions to ask vendors
- Do you perform route origin validation and drop RPKI-invalid routes, on all sessions or only some?
- Have you published ROAs for the address space you assign to us?
- If we bring our own addresses, will you check our ROAs before turning up BGP?
- Who will create and maintain our ROAs, and how are changes coordinated with provider changes?
- How do you monitor for hijacks or invalid announcements of our prefixes?
How it differs from PKI
Public key infrastructure (PKI) is the general system of certificate authorities and certificates used to prove identities for websites, users, devices and email. RPKI uses the same cryptographic building blocks for a single, narrow job: proving who holds IP address space and AS numbers, and letting address holders state which ASNs may originate routes for their prefixes. Its certificate authorities are the regional internet registries, not commercial certificate providers, and its records are used by routers, not browsers. Buying web or device certificates does nothing for routing security, and RPKI does nothing for website encryption.
