Independent RPKI publication servers play a critical role in securing Internet routing by allowing network operators to cryptographically authorize IP address prefixes and prevent malicious BGP hijacking attempts.
Key Points
- Resource Public Key Infrastructure (RPKI) uses Route Origin Authorizations (ROAs) to verify that an Autonomous System (AS) is authorized to announce specific IP address prefixes.
- While five global Regional Internet Registries (RIRs) manage most RPKI data, a "long tail" of smaller, independent servers exists for operational control, cross-registry management, and research.
- Researchers analyzed 3,778 ROA objects across 1,163 unique ASes, finding that 91% of these objects are cryptographically valid.
- Over 50% of analyzed ROAs use the "maxLength" parameter, which can inadvertently increase vulnerability to sub-prefix hijacks if not configured according to RFC 9319 guidelines.
- The study identified that 19.6% of ROAs using maxLength lack corresponding BGP announcements, creating potential security risks for those specific network segments.