cc-pipe: Breaking Systemic Bottlenecks in RPKI Data Supply Chain with Concurrent and Conflict-Free Pipelines
Chenhui Yu, Yanbiao Li, Hui Zou, Yuxuan Chen, Shiyi Liu, Gaogang Xie
Abstract
While the Resource Public Key Infrastructure (RPKI) is essential for securing BGP, the high latency, limited scalability, and vulnerabilities in the data supply chain severely undermine its security guarantees and impede network operations. Within this supply chain, existing research identifies the Relying Party (RP) validation process as the primary performance bottleneck. This bottleneck originates from the standard monolithic architecture, which enforces strong consistency but incurs high latency. Previous work has pursued incremental optimizations within this architecture, yet achieving substantial gains remains difficult.
Based on extensive measurements, we identify inherent blocking within the paradigm as the root cause. To address this, we propose cc-pipe, a novel pipeline architecture that breaks the fundamental consistency-latency trade-off. By leveraging a predictive conflict graph, cc-pipe enables low-latency incremental data dissemination while preserving strong consistency guarantees. Evaluation with real-world deployment demonstrates that cc-pipe reduces average latency by up to 73.3% across all data with negligible router overhead. It also delivers significant scalability under projected future workloads, as well as robust resilience to misbehaving publication points.
Ask about this paper
Your agent reads all of it.
Lune indexed this paper to the last equation, along with the top-tier papers that cite it. Ask a question and the answer quotes them.
Your agent calls
Luneget_paper_fulltext
Free to start. No credit card required.
Terminal
Install the CLIlune papers fulltext 6cedb965-e891-4f3a-a41a-f99f3d94a57aBuilds on6
- Hijacking Bitcoin: Routing Attacks on CryptocurrenciesMaria Apostolaki, Aviv Zohar, Laurent VanbeverS&P 2017 · 473 citations
- Are We There Yet? On RPKI's Deployment and SecurityYossi Gilad, Avichai Cohen, Amir Herzberg, Michael Schapira et al.NDSS 2017 · 108 citations
- Beyond Limits: How to Disable Validators in Secure NetworksTomas Hlavacek, Philipp Jeitner, Donika Mirdita, Haya Schulmann et al.SIGCOMM 2023 · 14 citations
- The Hanging ROA: A Secure and Scalable Encoding Scheme for Route Origin AuthorizationYanbiao Li, Hui Zou, Yuxuan Chen, Yinbo Xu et al.INFOCOM 2022 · 6 citations
- Pruning the Tree: Rethinking RPKI Architecture from the Ground upHaya Schulmann, Niklas VogelNDSS 2026 · 1 citation
Related papers
- Byzantine-Secure Relying Party for Resilient RPKIJens Frieß, Donika Mirdita, Haya Schulmann, Michael WaidnerCCS 2024 · 1 citation
- SoK: An Introspective Analysis of RPKI SecurityDonika Mirdita, Haya Schulmann, Michael WaidnerUSENIX Security 2025
- dRR: A Decentralized, Scalable, and Auditable Architecture for RPKI RepositoryYingying Su, Dan Li, Li Chen, Qi Li et al.NDSS 2024
- Stalloris: RPKI Downgrade AttackTomas Hlavacek, Philipp Jeitner, Donika Mirdita, Haya Schulmann et al.USENIX Security 2022
- The Fault in Our Drafts: Vulnerabilities in RPKI Specification and SoftwareOliver Jacobsen, Tobias Kirsch, Haya Schulmann, Niklas Vogel et al.S&P 2026
