Table of contents
Quick Learnings:
Internet Number Resources and Their Allocation
What is BGP?
How Does RPKI Work?
Why Should RPKI Be Used?
Adoption and Future of RPKI
Conclusion
FAQ
What Is RPKI? Resource Public Key Infrastructure For Beginners
Here's all you need to know about the Resource Public Key Infrastructure, how it works and how to use it.
Quick Learnings:
- RPKI enhances the security of the Border Gateway Protocol (BGP) by using cryptographic certificates to validate that Autonomous Systems (AS) are the legitimate originators of IP prefixes. This prevents fraudulent or mistaken routing announcements.
- RPKI employs a system of cryptographic validation through Route Origin Authorizations (ROAs) and the RTR protocol, which ensures that BGP routers only accept valid route announcements, blocking malicious or erroneous routes from propagating.
- While RPKI adoption is growing, it remains underutilized, with only around 40% of networks using it. Widespread implementation is crucial to safeguard internet routing and reduce vulnerabilities like outages, fraud, and data breaches.
RPKI stands for Resource Public Key Infrastructure. In simple terms, it is a security framework that enables network operators to secure the routing infrastructure. In not-so-simple terms, it is a framework that associates Internet Protocol address ranges with autonomous system numbers – IPs with ASNs – using cryptographic signatures to perform route origin validation.
What is RPKI used for specifically? To put it plainly: to prevent route hijacks and leaks within the internet’s routing infrastructure supported by the Border Gateway Protocol (BGP). The Internet Engineering Task Force (IETF) introduced the PRKI framework in 2012 to support secure internet routing. Regional Internet Registries (RIRs) play a key role in this process.
RIRs assign IPs and ASNs as well as issue certificates to legitimate IP address holders. A resource certificate acts like a digital signature, allowing the holder to generate Route Origination Authorizations (ROAs) and enable autonomous systems to originate routes to one or more prefixes. Both certificates and ROAs are publicly accessible, enabling the creation of filters that BGP routers use to validate prefix announcements.
Before diving into BGP, autonomous systems, RPKI, and ROAs, let’s first explore internet number resources and their allocation.
Internet Number Resources and Their Allocation
As RPKI does not exist without IP addresses and AS numbers, it is important to understand how these resources are allocated. Here’s a quick rundown.
The Internet Assigned Numbers Authority (IANA) is the central repository for all internet number resources. Lower in the hierarchy, Regional Internet Registries assign IP addresses and ASNs, while Local Internet Registries (LIRs) allocate resources to end users. With IPv4 exhaustion, IPv6 is becoming increasingly critical, complementing RPKI’s role in securing routing.

Let’s explore the roles of RIRs and LIRs more closely.
Regional Internet Registries
Five RIRs exist in total, and each Regional Internet Registry is responsible for a different geographical region:
- African Network Information Center (AFRINIC) operates in Africa
- Asia-Pacific Network Information Center (APNIC) operates in Asia and Oceania
- American Registry for Internet Numbers (ARIN) operates in North America and parts of the Caribbean
- Latin America and Caribbean Network Information Center (LACNIC) operates in Latin America and parts of the Caribbean
- Réseaux IP Européens Network Coordination Center (RIPE NCC) operates in Europe and parts of Asia
RIRs allocate IPs and ASNs to resource holders according to strict rules and regulations, which were first implemented partly due to the poor management of the same resources in the early days of the internet. Before the emergence of RIRs. Today, IANA has no more resources to allocate, and RIRs are responsible for managing what’s left of the 4.29 billion IPv4 address pool.
That said, RIRs do not allocate resources to an end user (i.e., resource holder). LIRs are, in fact, the ones responsible for allocating resources to actual internet users.
Local Internet Registries
A Local Internet Registry is an organization that a RIR approves to provide services in its region. In many cases, that is an internet service provider (ISP), an educational institution or another trusted organization that has the LIR status and can allocate internet number resources.
IPXO has the LIR status and is a member of RIPE NCC, which enables us to provide managed LIR services in the region.
What is BGP?
The Border Gateway Protocol is an essential routing protocol responsible for directing IP packets between autonomous systems. Whenever someone submits data on the internet, BGP makes routing decisions by reflecting on all available paths, local routing policies or rule sets configured by network operators. If the chosen path goes down, BGP swiftly finds a new one to ensure the network’s stability.

Undeniably, BGP is the backbone of the internet. Without it, internet routers couldn’t communicate, and packets wouldn’t reach the specific IP address blocks within the AS.
To better understand how BGP works, it’s important to get familiar with autonomous systems and the IP address space.
Autonomous system
An AS is a group of large networks that make up the internet. A network or a group of networks owns an autonomous system, which a resource holder manages.
A single AS consists of numerous different subnetworks that share a common internet routing logic and routing policies. A routing policy consists of an IP space and other autonomous systems it can connect to.
Address space
An IP address space is a range of IP address prefixes controlled by an AS. The IP address prefix identifies the network. Meanwhile, the prefix length specifies a range of devices within the same network. The prefix length can be expressed as a slash (/). For example, 192.0.2.1/24.
To identify autonomous systems, IANA allocates each of them a unique 16-digit autonomous system number (ASN).
IANA presents the autonomous system number in the AS(#) format. An ASN can be between 1 and 65534 or represent 32-bit numbers from 131072 to 4294967294. For example, IPXO’s ASN is AS834, and Google’s is AS15169.
The sole purpose of an ASN is to communicate with other autonomous systems. With its help, the Border Gateway Protocol can quickly navigate between unique AS paths across the internet.

How Does RPKI Work?
The RTR (RPKI to Router) protocol enables BGP routers to query RPKI validators for verification data. Popular validators include Routinator (by NLnet Labs) and OctoRPKI (by Cloudflare). These tools aggregate ROA data, process cryptographic information, and deliver it to routers for real-time validation. This prevents invalid route announcements from propagating.
While BGP is efficient at path validation, it cannot validate routing information on its own. This makes the internet highly susceptible to attacks. For example, in 2018, a BGP hijack incident caused Google Cloud traffic to be rerouted through a Nigerian ISP. Such incidents highlight why frameworks like RPKI are critical for internet stability and security.
RPKI prevents such vulnerabilities by cryptographically verifying whether an AS legitimately originates its IP prefix announcement. This process involves Route Origin Authorization (ROA) and Route Origin Validation (ROV).
ROA and ROV
Route Origin Authorization is a cryptographic certificate structure, also known as a public key, that can fix an address to an AS. In this certificate structure, the public key is part of a key pair that also consists of a private key.
ROAs contain a number of crucial routing parameters, such as origin ASN, specific prefix and maximum length. Certificate authorities (CAs or trust anchors), generate ROAs, and resource holders usually run them.
Resource certification authorities include the Internet Assigned Numbers Authority, Regional Internet Registries, Local Internet Registries or internet service providers, depending on the RPKI hierarchy.
Each regional internet registry has a trust anchor that can specify the route to the verified routing data of a particular RPKI repository. A trust anchor is a file that allows relying parties to retrieve RPKI data from the RPKI repository.
Since RPKI data stands outside of BGP, network operators need to use Route Origin Validation to exchange information with RPKI architecture. An RPKI validator (relying party software) takes care of that. After RPKI extracts ROA data from every CA, RPKI validators present it to the paired routers. They also handle all the crypto processing of the received data.

For routers to query RPKI validators, the lightweight protocol called RTR (RPKI to Router Protocol) gets involved. Essentially, it receives aggregated ROA data and then transfers it to BGP.
Then, RTR compares a BGP route announcement with the collected data. If it appears invalid, the protocol rejects the announcement, stopping bad actors in their tracks.
Why Should RPKI Be Used?
The RPKI system solves several of BGP’s routing problems, such as initially distributed mistakes, human error (e.g., typos) and malicious agents. But RPKI’s primary focus is to provide the most efficient out-of-band BGP routing security currently available.
For one, it plays a crucial role in preventing route hijacking. A route hijack is either a malicious or accidental unauthorized route origination, resulting in critical outages or fraudulent traffic manipulation.
Furthermore, RPKI provides resource holders with proof of ownership to use and distribute resources through a signed resource certification.
But it’s not only the enterprises and other resource authorities who benefit from RPKI. Regular internet users do too. The framework can prevent personal data breaches and redirection to malicious sites.
Note that if you want RPKI deployed to secure BGP, you must choose an ISP provider that implements RPKI validation.
Adoption and Future of RPKI
Despite being introduced over a decade ago, RPKI adoption remains uneven. As of 2024, approximately 40% of global networks perform RPKI-based route validation, according to reports by MANRS and APNIC. Increasing awareness and implementation of RPKI are vital to mitigating routing vulnerabilities worldwide.
Organizations, ISPs, and enterprises are encouraged to implement RPKI validation not only to secure their infrastructure but also to protect end users from outages, data breaches, and malicious redirects. Transitioning to IPv6 alongside RPKI adoption further enhances routing security and efficiency.
Conclusion
The BGP protocol, originally intended to operate on a trust-based model, is highly vulnerable to threats such as route leaks, hijacks, and human error. The Resource Public Key Infrastructure (RPKI) framework provides a critical additional security layer, ensuring that routing announcements are cryptographically validated and legitimate.
While RPKI adoption has grown in recent years, more widespread implementation is needed to protect internet routing comprehensively. By deploying RPKI and combining it with IPv6 adoption, the internet can achieve greater stability, security, and reliability.
FAQ
RPKI (Resource Public Key Infrastructure) is a framework that secures the Border Gateway Protocol (BGP) by using cryptographic certificates to verify the legitimacy of route announcements. It is important for preventing route hijacks, leaks, and ensuring secure internet routing.
RPKI prevents route hijacks and leaks by using Route Origin Authorizations (ROAs), which bind IP address prefixes to Autonomous System Numbers (ASNs). These cryptographic certificates allow routers to validate that a route announcement is legitimate and prevents invalid routes from being propagated.
The RTR (RPKI to Router) protocol is used by BGP routers to query RPKI validators for real-time route validation data. It helps verify route announcements by comparing them with the validated information from RPKI, ensuring that only authorized routes are accepted.
Route Origin Authorizations (ROAs) are cryptographic certificates that specify which Autonomous Systems are allowed to announce certain IP prefixes. ROAs are generated by Certificate Authorities and enable Route Origin Validation (ROV), ensuring only legitimate BGP announcements are accepted.
To implement RPKI, network operators need to choose an ISP that supports RPKI validation and generate ROAs for their IP address prefixes. Additionally, RPKI validators like Routinator and OctoRPKI can be used to verify BGP route announcements, ensuring secure and accurate routing.
About the author
Related reading
Why residential proxy detection is so difficult
Residential proxies have always been harder to detect than datacenter proxies. They operate via real residential IP addresses, assigned by ISPs, which makes the traffic…
Read more
Managing IP infrastructure at scale: challenges and modern solutions
One of the less-discussed yet highly relevant layers of managing modern internet infrastructure lies in IP infrastructure management. Even though it doesn’t get the same…
Read more
What Is a Network Source of Truth (NSoT) and Why It Matters for Modern IP Management
A reliable Network Source of Truth (NSoT) gives network teams full visibility and control by unifying IP data, automation, and compliance. Learn how IPXO helps organizations simplify network management…
Read moreSubscribe to the IPXO email and don’t miss any news!