USENIX Security2025Top-tier venue
SoK: An Introspective Analysis of RPKI Security
Donika Mirdita, Haya Schulmann, Michael Waidner
Abstract
The Resource Public Key Infrastructure (RPKI) is the main mechanism to protect inter-domain routing with BGP from prefix hijacks. It has already been widely deployed by large providers and the adoption rate is getting to a critical point. Almost half of all the global prefixes are now covered by RPKI and measurements show that 27% of networks are already using RPKI to validate BGP announcements. Over the past 10 years, there has been much research effort in RPKI, analyzing different facets of the protocol, such as software vulnerabilities, robustness of the infrastructure or the proliferation of RPKI validation. In this work we compile the first systemic overview of the vulnerabilities and misconfigurations in RPKI and quantify the security landscape of the global RPKI deployments based on our measurements and analysis. Our study discovers that 56% of the global RPKI validators suffer from at least one documented vulnerability. We also do a systematization of knowledge for existing RPKI security research and complement the existing knowledge with novel measurements in which we discover new trends in availability of RPKI repositories, and their communication patterns with the RPKI validators. We weave together the results of existing research and our study, to provide a comprehensive tableau of vulnerabilities, their sources, and to derive future research paths necessary to prepare RPKI for full global deployment.
Ask about this paper
Your agent reads all of it.
Lune indexed this paper to the last equation, along with the top-tier papers that cite it. Ask a question and the answer quotes them.
Your agent calls
Luneget_paper_fulltext
Free to start. No credit card required.
Terminal
Install the CLIlune papers fulltext 2b2503b8-27bb-4d68-82d3-7dca6ee68e01Cited by top-tier papers3
- The Fault in Our Drafts: Vulnerabilities in RPKI Specification and SoftwareOliver Jacobsen, Tobias Kirsch, Haya Schulmann, Niklas Vogel et al.S&P 2026
- cc-pipe: Breaking Systemic Bottlenecks in RPKI Data Supply Chain with Concurrent and Conflict-Free PipelinesChenhui Yu, Yanbiao Li, Hui Zou, Yuxuan Chen et al.NSDI 2026
- Crack in the Armor: Underlying Infrastructure Threats to RPKI Publication Point ReachabilityYunhao Liu, Jessie Hui Wang, Yuedong Xu, Zongpeng Li et al.NDSS 2026
Builds on10
- Are We There Yet? On RPKI's Deployment and SecurityYossi Gilad, Avichai Cohen, Amir Herzberg, Michael Schapira et al.NDSS 2017 · 108 citations
- Augur: Internet-Wide Detection of Connectivity DisruptionsPaul Pearce, Roya Ensafi, Frank Li, Nick Feamster et al.S&P 2017 · 84 citations
- Beyond Limits: How to Disable Validators in Secure NetworksTomas Hlavacek, Philipp Jeitner, Donika Mirdita, Haya Schulmann et al.SIGCOMM 2023 · 14 citations
- Behind the Scenes of RPKITomas Hlavacek, Philipp Jeitner, Donika Mirdita, Haya Schulmann et al.CCS 2022 · 14 citations
- Privacy Preserving and Resilient RPKIKris Shrishak, Haya SchulmannINFOCOM 2021 · 5 citations
Related papers
- Keep Your Friends Close, but Your Routeservers Closer: Insights into RPKI Validation in the InternetTomas Hlavacek, Haya Schulmann, Niklas Vogel, Michael WaidnerUSENIX Security 2023
- Demystifying RPKI-Invalid Prefixes: Hidden Causes and Security RisksWeitong Li, Tao Wan, Tijay ChungNDSS 2026
- Stalloris: RPKI Downgrade AttackTomas Hlavacek, Philipp Jeitner, Donika Mirdita, Haya Schulmann et al.USENIX Security 2022
- The CURE to Vulnerabilities in RPKI ValidationDonika Mirdita, Haya Schulmann, Niklas Vogel, Michael WaidnerNDSS 2024
- ROV-MI: Large-Scale, Accurate and Efficient Measurement of ROV DeploymentWenqi Chen, Zhiliang Wang, Dongqi Han, Chenxin Duan et al.NDSS 2022
