From Address Blocks to Authorized Prefixes: Redesigning RPKI ROV with a Hierarchical Hashing Scheme for Fast and Memory-Efficient Validation
Zedong Ni, Yinbo Xu, Hui Zou, Yanbiao Li, Guang Cheng, Gaogang Xie
Abstract
Route Origin Validation (ROV) with Route Origin Authorizations (ROAs), built on top of the Resource Public Key Infrastructure (RPKI), serves as the only formally standardized and production-grade defense mechanism against route hijackings in global interdomain routing infrastructures. However, the widespread adoption of RPKI has introduced escalating scalability challenges in validating high volumes of route messages against massive ROA entries.
In this paper, we attribute the performance bottleneck of existing ROV schemes to their underlying validation model, where the route is matched against rules in the form of address blocks. To overcome this bottleneck, we propose the Authorized Prefix (AP) model that enables validation at the prefix granularity, and redesign RPKI ROV based on this new model with a hierarchical hashing scheme named h 2 ROV. Extensive evaluations verify h 2 ROV's superiority over state-of-the-art approaches in IPv4, with a speedup of 1.7× ∼ 9.8× in validation and a reduction of 49.3% ∼ 86.6% in memory consumption. System emulations using real-world network topologies further demonstrate h 2 ROV confines its impact to routing convergence to below 8.5% during update burst events, while reducing ROV-induced delays by 30.4% ∼ 64.7% compared to existing solutions.
Ask about this paper
Your agent reads all of it.
Lune indexed this paper to the last equation, along with the top-tier papers that cite it. Ask a question and the answer quotes them.
Your agent calls
Luneget_paper_fulltext
Free to start. No credit card required.
Terminal
Install the CLIlune papers fulltext 7018601e-fa7d-434a-a1c6-b33cae4dcc27Cited by top-tier papers1
Ask how each one uses itBuilds on6
- Are We There Yet? On RPKI's Deployment and SecurityYossi Gilad, Avichai Cohen, Amir Herzberg, Michael Schapira et al.NDSS 2017 · 108 citations
- The Next Generation of BGP Data Collection PlatformsThomas Alfroy, Thomas Holterbach, Thomas Krenc, K. C. Claffy et al.SIGCOMM 2024 · 20 citations
- The Hanging ROA: A Secure and Scalable Encoding Scheme for Route Origin AuthorizationYanbiao Li, Hui Zou, Yuxuan Chen, Yinbo Xu et al.INFOCOM 2022 · 6 citations
- ROV++: Improved Deployable Defense against BGP HijackingReynaldo Morillo, Justin Furuness, Cameron Morris, James Breslin et al.NDSS 2021
- Keep Your Friends Close, but Your Routeservers Closer: Insights into RPKI Validation in the InternetTomas Hlavacek, Haya Schulmann, Niklas Vogel, Michael WaidnerUSENIX Security 2023
Related papers
- ROV-MI: Large-Scale, Accurate and Efficient Measurement of ROV DeploymentWenqi Chen, Zhiliang Wang, Dongqi Han, Chenxin Duan et al.NDSS 2022
- Demystifying RPKI-Invalid Prefixes: Hidden Causes and Security RisksWeitong Li, Tao Wan, Tijay ChungNDSS 2026
- Right the Ship: Assessing the Legitimacy of Invalid Routes in RPKIAndong Chen, Yangyang Wang, Jia Zhang, Mingwei XuCCS 2025
- ImpROV: Measurement and Practical Mitigation of Collateral Damage in RPKI Route Origin ValidationWeitong Li, Yuze Li, Taejoong ChungUSENIX Security 2025
- iROV: Breaking the Silence of RPKI with Interactive ValidationYounsoo Kim, Seungjin Baek, Weitong Li, Tijay Chung et al.USENIX Security 2026
