Are We There Yet? On RPKI's Deployment and Security
Yossi Gilad, Avichai Cohen, Amir Herzberg, Michael Schapira, Haya Schulmann
Abstract
The Resource Public Key Infrastructure (RPKI) binds IP address blocks to owners' public keys. RPKI enables routers to perform Route Origin Validation (ROV), thus preventing devastating attacks such as IP prefix hijacking. Yet, despite extensive effort, RPKI's deployment is frustratingly sluggish, leaving the Internet largely insecure. We tackle fundamental questions regarding today's RPKI's deployment and security: What is the adoption status of RPKI and ROV? What are the implications for global security of partial adoption? What are the root-causes for slow adoption? How can deployment be pushed forward? We address these questions through a combination of empirical analyses, a survey of over 100 network practitioners, and extensive simulations. Our main contributions include the following. We present the first study measuring ROV enforcement, revealing disappointingly low adoption at the core of the Internet. We show, in contrast, that without almost ubiquitous ROV adoption by large ISPs significant security benefits cannot be attained. We next expose a critical security vulnerability: about a third of RPKI authorizations issued for IP prefixes do not protect the prefix from hijacking attacks. We examine potential reasons for scarce adoption of RPKI and ROV, including human error in issuing RPKI certificates and inter-organization dependencies, and present recommendations for addressing these challenges.
Ask about this paper
Your agent reads all of it.
Lune indexed this paper to the last equation, along with the top-tier papers that cite it. Ask a question and the answer quotes them.
Your agent calls
Luneget_paper_fulltext
Free to start. No credit card required.
Terminal
Install the CLIlune papers fulltext 4372c013-92cc-4526-a563-99ee3dba7b05Cited by top-tier papers29
- Bamboozling Certificate Authorities with BGPHenry Birge-Lee, Yixin Sun, Anne Edmundson, Jennifer Rexford et al.USENIX Security 2018 · 83 citations
- SICO: Surgical Interception Attacks by Manipulating BGP CommunitiesHenry Birge-Lee, Liang Wang, Jennifer Rexford, Prateek MittalCCS 2019 · 51 citations
- A System to Detect Forged-Origin BGP HijacksThomas Holterbach, Thomas Alfroy, Amreesh Phokeer, Alberto Dainotti et al.NSDI 2024 · 21 citations
- Learning with Semantics: Towards a Semantics-Aware Routing Anomaly Detection SystemYihao Chen, Qilei Yin, Qi Li, Zhuotao Liu et al.USENIX Security 2024 · 14 citations
- From IP to transport and beyond: cross-layer attacks against applicationsTianxiang Dai, Philipp Jeitner, Haya Schulmann, Michael WaidnerSIGCOMM 2021 · 14 citations
Related papers
- SoK: An Introspective Analysis of RPKI SecurityDonika Mirdita, Haya Schulmann, Michael WaidnerUSENIX Security 2025
- Demystifying RPKI-Invalid Prefixes: Hidden Causes and Security RisksWeitong Li, Tao Wan, Tijay ChungNDSS 2026
- ROV-MI: Large-Scale, Accurate and Efficient Measurement of ROV DeploymentWenqi Chen, Zhiliang Wang, Dongqi Han, Chenxin Duan et al.NDSS 2022
- Right the Ship: Assessing the Legitimacy of Invalid Routes in RPKIAndong Chen, Yangyang Wang, Jia Zhang, Mingwei XuCCS 2025
- From Address Blocks to Authorized Prefixes: Redesigning RPKI ROV with a Hierarchical Hashing Scheme for Fast and Memory-Efficient ValidationZedong Ni, Yinbo Xu, Hui Zou, Yanbiao Li et al.NSDI 2025 · 3 citations
