dRR: A Decentralized, Scalable, and Auditable Architecture for RPKI Repository
Yingying Su, Dan Li, Li Chen, Qi Li, Sitong Ling
Abstract
Although Resource Public Key Infrastructure (RPKI) is critical for securing inter-domain routing, we find that its key component, the RPKI Repository, is under studied. We conduct the first data-driven analysis of the existing RPKI Repository infrastructure, including a survey of worldwide AS administrators and a large-scale measurement of the existing RPKI Repository. Based on the findings of our study, we identify three key problems. Firstly, misbehaving RPKI authorities can easily manipulate RPKI objects, and Internet Number Resources holders (INRs holders) and Relying Parties (RPs) can neither prevent malicious behaviors of misbehaving authorities nor hold them accountable. Secondly, RPKI Repository is sensitive to failures: An attack or downtime of any repository Publication Point (PP) will prevent RPs from obtaining complete RPKI object views. Finally, we identify scalability issues with the current RPKI Repository, which are expected to worsen with the further deployment of Route Origin Authorization (ROA).
To address these problems, we propose dRR, an architecture that enhances the security, robustness, and scalability of the RPKI Repository while being compatible with standard RPKI. By introducing two new entities: Certificate Servers (CSs) and Monitors, dRR forms a decentralized federation of CSs, which enables the RPKI Repository to proactively defend against malicious behavior from authorities and to tolerate PPs' failures. dRR is also scalable for future large-scale deployment. We present the design of dRR in detail and implement a prototype of dRR on a global Internet testbed spanning 15 countries. Experimental results show that, although new security features are introduced, dRR only incurs negligible latency for certificate issuance and revocation. The throughput of certificate updates achieved by dRR is 450 times higher than the current maximum RPKI certificate update frequency. 2 We have summarized all abbreviations used in dRR in Appendix B
Ask about this paper
Your agent reads all of it.
Lune indexed this paper to the last equation, along with the top-tier papers that cite it. Ask a question and the answer quotes them.
Your agent calls
Luneget_paper_fulltext
Free to start. No credit card required.
Terminal
Install the CLIlune papers fulltext dadb71a3-7693-4dcd-ab42-5babed1b0273Cited by top-tier papers5
- Pruning the Tree: Rethinking RPKI Architecture from the Ground upHaya Schulmann, Niklas VogelNDSS 2026 · 1 citation
- The Fault in Our Drafts: Vulnerabilities in RPKI Specification and SoftwareOliver Jacobsen, Tobias Kirsch, Haya Schulmann, Niklas Vogel et al.S&P 2026
- SoK: An Introspective Analysis of RPKI SecurityDonika Mirdita, Haya Schulmann, Michael WaidnerUSENIX Security 2025
- Crack in the Armor: Underlying Infrastructure Threats to RPKI Publication Point ReachabilityYunhao Liu, Jessie Hui Wang, Yuedong Xu, Zongpeng Li et al.NDSS 2026
- Understanding Route Origin Validation (ROV) Deployment in the Real World and Why MANRS Action 1 Is Not FollowedLancheng Qin, Li Chen, Dan Li, Honglin Ye et al.NDSS 2024
Builds on7
- The Honey Badger of BFT ProtocolsAndrew Miller, Yu Xia, Kyle Croman, Elaine Shi et al.CCS 2016 · 974 citations
- Byzantine Ordered Consensus without Byzantine OligarchyYunhao Zhang, Srinath T. V. Setty, Qi Chen, Lidong Zhou et al.OSDI 2020 · 131 citations
- Kauri: Scalable BFT Consensus with Pipelined Tree-Based Dissemination and AggregationRay Neiheiser, Miguel Matos, Luís E. T. RodriguesSOSP 2021 · 65 citations
- Behind the Scenes of RPKITomas Hlavacek, Philipp Jeitner, Donika Mirdita, Haya Schulmann et al.CCS 2022 · 14 citations
- Privacy Preserving and Resilient RPKIKris Shrishak, Haya SchulmannINFOCOM 2021 · 5 citations
Related papers
- Are We There Yet? On RPKI's Deployment and SecurityYossi Gilad, Avichai Cohen, Amir Herzberg, Michael Schapira et al.NDSS 2017 · 108 citations
- Demystifying RPKI-Invalid Prefixes: Hidden Causes and Security RisksWeitong Li, Tao Wan, Tijay ChungNDSS 2026
- Stalloris: RPKI Downgrade AttackTomas Hlavacek, Philipp Jeitner, Donika Mirdita, Haya Schulmann et al.USENIX Security 2022
- ROV-MI: Large-Scale, Accurate and Efficient Measurement of ROV DeploymentWenqi Chen, Zhiliang Wang, Dongqi Han, Chenxin Duan et al.NDSS 2022
- Byzantine-Secure Relying Party for Resilient RPKIJens Frieß, Donika Mirdita, Haya Schulmann, Michael WaidnerCCS 2024 · 1 citation
